bigbox

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The install path is relatively trustworthy because it uses the vendor-scoped npm package, but the skill’s stated purpose and actual documentation are badly mismatched: BigBox/Box-style storage, Best Buy docs, and Home Depot actions cannot all be correct. The Membrane-mediated auth/data flow is disclosed and may be legitimate for this ecosystem, but it introduces third-party credential/data handling and is harder to justify when the target service itself is unclear.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
May 3, 2026, 09:49 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbigbox%2F@e35128b7d5cba9de78b453aeed94fc4ec2b61dfc
Security Audit — socket — bigbox