assemblyai
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's purpose mostly matches transcript-management tasks, and the install source is the official npm registry rather than an unverifiable binary. However, it shifts all authenticated AssemblyAI access through the third-party Membrane CLI and proxy layer, so credentials and data are mediated by an intermediary instead of going directly to AssemblyAI. That makes the footprint broader than necessary and raises medium risk, but not enough evidence supports a malicious classification.
Confidence: 86%Severity: 56%
Audit Metadata