beeswax

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities generally match its Beeswax-management purpose and the CLI comes from an official npm package, so this is not overtly malicious. The main concern is data-flow integrity: all authentication and API traffic are funneled through Membrane as an intermediary, with server-side credential handling and proxy requests, which is a meaningful trust expansion beyond direct Beeswax access. Overall this looks coherent but medium risk due to third-party credential delegation, proxying, mutable CLI install, and support for state-changing actions.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
May 1, 2026, 02:25 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbeeswax%2F@48cb655b3df5e78751365dcb1567fb23fa372de1
Security Audit — socket — beeswax