asana

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core purpose is coherent, and the installer appears to be an official npm package, so this is not malware-like. However, the skill routes authentication and Asana API access through Membrane as an intermediary rather than directly to Asana, creating meaningful third-party trust and data-flow risk; combined with mutable @latest installation and write/delete capabilities, this is medium risk but not malicious.

Confidence: 89%Severity: 56%
Audit Metadata
Analyzed At
Sep 20, 2026, 12:09 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fasana%2F@5a219d626d5475fb7b822876291c6eda6d65f661f571fc901c21772c741d5d45
Security Audit — socket — asana