arangodb

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is not overtly malicious and its install path appears to use a legitimate first-party npm package, but its actual footprint is broader than a direct ArangoDB integration: all authentication, connection management, and data actions are routed through Membrane. That intermediary data flow and delegated credential handling create a medium security risk, amplified by the unpinned global CLI install and minor publisher-identity mismatch.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 30, 2026, 06:51 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Farangodb%2F@6c41f3deb3e93ab946f7a796a67364591c3dc126
Security Audit — socket — arangodb