autobound

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and capabilities mostly align, and the CLI comes from an official npm package rather than an opaque binary. However, all Autobound access is mediated through Membrane, the skill installs and relies on a third-party CLI with an unpinned global install, and authenticated business data/actions flow through that intermediary platform rather than directly to Autobound. This is not confirmed malware, but it carries medium risk due to intermediary credential/data handling and remote action execution.

Confidence: 83%Severity: 56%
Audit Metadata
Analyzed At
Apr 30, 2026, 11:37 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fautobound%2F@0743f3a621fb805befc8a795439f2c7cf823962a
Security Audit — socket — autobound