assemblyai

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities mostly align, and the CLI install source appears legitimate, but all AssemblyAI access and credentials are mediated through Membrane rather than the official API. That third-party proxy model is a material data-flow and credential-forwarding risk, though not enough to call the skill malicious.

Confidence: 87%Severity: 64%
Audit Metadata
Analyzed At
Apr 30, 2026, 09:40 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fassemblyai%2F@105159dc475741e6223d3219111caea2950ced76
Security Audit — socket — assemblyai