azure-ai-vision

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is internally coherent and not overtly malicious, but it routes Azure AI Vision access and authentication through Membrane rather than directly to Azure. Because this third-party mediation is central to the skill, disclosed, and supported by the vendor's docs, this looks like a managed integration pattern rather than credential theft; still, the extra trust boundary and unpinned CLI install make it medium risk.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 09:14 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fazure-ai-vision%2F@1e6767b1120ca981dc4fb0b8d7cf6c9ec50e03e7