brandfetch

Warn

Audited by Socket on Sep 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose is plausible, but it unnecessarily inserts Membrane as a third-party auth and API proxy instead of using Brandfetch's direct official API flow. The npm install path is legitimate and not malware-like, but the expanded trust boundary, credential handling by a separate platform, and mutable `@latest` install make this a medium-risk skill.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Sep 21, 2026, 12:09 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbrandfetch%2F@7207e7fa927e579fef2f8918a890b8de64f7a3683684951ff9655b518d78232a
Security Audit — socket — brandfetch