buildchatbot

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The npm-installed Membrane CLI appears official and not overtly malicious, but the skill’s stated BuildChatbot purpose is undermined by an inconsistent official-doc link and by routing authentication and action execution through Membrane instead of a clearly verified first-party BuildChatbot API. This is best classified as medium risk due to third-party credential/data handling and service-identity ambiguity, not confirmed malware.

Confidence: 84%Severity: 59%
Audit Metadata
Analyzed At
May 2, 2026, 11:34 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbuildchatbot%2F@1bdde7fb0392bbe282bffe21f59af90ab8448dfa
Security Audit — socket — buildchatbot