bitly

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities broadly match its stated Bitly purpose, and the CLI comes from an official npm package tied to Membrane. However, all Bitly authentication and action execution are routed through Membrane infrastructure, so credentials and user data are mediated by a third party rather than going directly to Bitly. This is not clear malware, but it creates medium risk and a trust expansion that users should explicitly understand.

Confidence: 89%Severity: 56%
Audit Metadata
Analyzed At
Apr 30, 2026, 03:21 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbitly%2F@cc593454b02438e688c4482f52970ce004606026
Security Audit — socket — bitly