brick

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly coherent and uses an official npm-distributed Membrane CLI, so it does not look malicious. However, all Brick authentication and API access are funneled through Membrane as an intermediary rather than directly to Brick, and the Brick docs reference is inconsistent. This is a moderate trust and data-flow concern, not confirmed malware.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Apr 28, 2026, 10:05 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbrick%2F@d0783ca2f2877ac5b1d9b5d59e2c062c7da964c3
Security Audit — socket — brick