boostai

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent as a Membrane-based Boost.ai wrapper, and the CLI install path appears official. However, it routes authentication, credentials, and API activity through Membrane rather than directly to Boost.ai, creating meaningful third-party trust and data-flow risk; the main concern is mediated credential/data handling, not overt malware.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 01:45 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fboostai%2F@fe7c28dde7ddf78514ffef681bf11017810e41ef
Security Audit — socket — boostai