captain-data

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is coherent for a Captain Data integration and uses an official npm-distributed CLI, so it does not look malicious. However, it routes authentication, API access, and data through Membrane as an intermediary rather than directly to Captain Data, and it installs an unpinned external CLI; this creates meaningful trust and data-flow risk even though the overall footprint is proportionate to the stated purpose.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 1, 2026, 06:10 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcaptain-data%2F@670cda43cd26acf476e379512b66f4accc077e01
Security Audit — socket — captain-data