bland-ai

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is partly coherent as a Membrane connector guide, and its install path is official npm-based, but it inaccurately claims Bland AI lacks public docs and routes authentication/data through Membrane rather than directly to Bland. That intermediary architecture may be expected for Membrane skills, yet it materially expands trust and enables real-world telephony actions, so overall risk is medium rather than benign.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
Apr 29, 2026, 03:21 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbland-ai%2F@6b92b6d93ffa112a6a2a750516bc871a1d89bf88
Security Audit — socket — bland-ai