bugbug

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities are broadly aligned, and the CLI comes from an official npm package tied to the same publisher, so this is not overtly malicious. However, the data flow is mediated through Membrane rather than directly to BugBug, meaning credentials and API activity are entrusted to a third-party platform; combined with mutable @latest installation, this creates medium security risk disproportionate to a simple BugBug integration.

Confidence: 90%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 04:53 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbugbug%2F@ab254d70996f68ac423d1c726b2d650a0d814821