bland-ai

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's basic function is coherent, and its CLI comes from an official npm package, but it unnecessarily intermediates Bland AI access through Membrane and contains a false claim that Bland lacks public documentation. This is not confirmed malware, but the third-party proxy/auth model and misleading service description create medium security risk.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
Sep 19, 2026, 06:36 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbland-ai%2F@2e042b4740b482e7b7cb5afd96787a53a18adb9a9984b1a079e5992cc8290b6a
Security Audit — socket — bland-ai