brass

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is coherent as a Membrane-powered Brass connector, and the CLI install path appears to use an official npm package rather than an opaque binary. However, the actual data flow is not direct Brass API usage: authentication, connection management, and action execution are routed through Membrane, so Brass data and delegated credentials pass through a third-party intermediary. That is disclosed and may be legitimate, but it materially increases trust and privacy risk versus a direct official-API integration.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Apr 30, 2026, 07:06 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbrass%2F@3c0676ae144549f351460dd9a8fea279fa46d1a4
Security Audit — socket — brass