canny

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly coherent as a Canny integration, and the CLI comes from an official npm package rather than an unverifiable binary. The main concern is data-flow integrity: Canny access is mediated through Membrane, so credentials, requests, and results pass through a third-party service and proxy layer instead of going directly to Canny. Combined with an unpinned global CLI install and broad proxy capability, this raises medium security risk, but the behavior is disclosed and not fundamentally incompatible with the stated purpose.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 09:15 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcanny%2F@0b253f64bd5d3ea694ea5253a54f2274edcc5d6b
Security Audit — socket — canny