botmaker

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s capabilities broadly match its stated Botmaker-management purpose, and the CLI install path appears official and proportionate. However, authentication and API traffic are mediated through Membrane rather than direct Botmaker endpoints, and the skill enables externally visible actions like sending messages; this creates medium risk from third-party credential/data routing and autonomous action potential, but not clear malicious intent.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:53 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbotmaker%2F@53e23b00d494b31391eb03c265b7a8f43b41875d
Security Audit — socket — botmaker