assemblyai

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose mostly matches transcript-management tasks, and the install source is the official npm registry rather than an unverifiable binary. However, it shifts all authenticated AssemblyAI access through the third-party Membrane CLI and proxy layer, so credentials and data are mediated by an intermediary instead of going directly to AssemblyAI. That makes the footprint broader than necessary and raises medium risk, but not enough evidence supports a malicious classification.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Sep 17, 2026, 02:11 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fassemblyai%2F@21d52c3ee07f7a4fa13b49e30f6169d2a07617925f1819a842a95f964af84d98
Security Audit — socket — assemblyai