assertible

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent in purpose, uses an official npm-distributed CLI, and does not obviously harvest local secrets, so it is not malware. However, it proxies Assertible access through Membrane, centralizes credentials and data in an intermediary service, and can create/run hosted actions from natural-language prompts, making the trust and data-flow footprint broader than a direct Assertible integration.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 30, 2026, 08:43 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fassertible%2F@6e2548b998b0c6794cb3b7322ebd65f95283fb09
Security Audit — socket — assertible