arcgis-online
Warn
Audited by Socket on Apr 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's stated ArcGIS purpose is plausible, and the CLI install source is relatively legitimate, but the actual integration routes authentication, requests, and data through Membrane instead of directly to ArcGIS Online. That intermediary architecture is a meaningful trust and data-flow expansion for a service-specific skill, so the main risk is third-party credential/data mediation rather than overt malware.
Confidence: 85%Severity: 66%
Audit Metadata