autodesk-revit

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities mostly align, and the CLI install path appears official via npm, so this is not overtly malicious. However, all Autodesk interaction is funneled through Membrane's managed proxy and credential layer rather than directly to Autodesk APIs, which introduces meaningful third-party data-flow and credential-forwarding risk; combined with unpinned CLI execution, this makes the skill moderately risky rather than benign.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 10:37 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fautodesk-revit%2F@7bd5f47a5c5ccb52566d35d7695dab10dd3202a3
Security Audit — socket — autodesk-revit