asana
Warn
Audited by Socket on Sep 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core purpose is coherent, and the installer appears to be an official npm package, so this is not malware-like. However, the skill routes authentication and Asana API access through Membrane as an intermediary rather than directly to Asana, creating meaningful third-party trust and data-flow risk; combined with mutable @latest installation and write/delete capabilities, this is medium risk but not malicious.
Confidence: 89%Severity: 56%
Audit Metadata