budgetsai

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly coherent as a Membrane connector guide and uses an official npm-published CLI from the same vendor, so there is no strong evidence of malware. Risk comes from routing authentication and Budgets.ai data through Membrane rather than directly to the service, use of an unpinned global CLI install, and incomplete verification of the claimed Budgets.ai target. This is better classified as medium security risk and low-to-moderate malware likelihood, not confirmed malicious behavior.

Confidence: 81%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 11:37 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbudgetsai%2F@5751f17b45f3a00f3189b26740b2603f7e112e1b
Security Audit — socket — budgetsai