bigid

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities broadly match its stated BigID integration purpose, and the CLI install source is official npm rather than an unverifiable binary. However, the real data path is not direct BigID access: authentication, connections, and action execution are mediated by Membrane, so sensitive BigID operations and outputs may be exposed to that third-party service. This is coherent but higher-trust than the description implies, making it medium risk rather than benign.

Confidence: 86%Severity: 57%
Audit Metadata
Analyzed At
Apr 30, 2026, 10:37 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbigid%2F@689d29ac7be015250c8b391edaa2e65f732d3053
Security Audit — socket — bigid