carapi

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose is CarAPI access, but its real footprint centers on Membrane as an intermediary for authentication, action discovery, and proxy requests. The npm install path is relatively legitimate, but the indirect credential and data flow through Membrane is disproportionate to a simple CarAPI integration and creates avoidable third-party exposure.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
Apr 28, 2026, 11:52 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcarapi%2F@dfc0991056112e2d0c7299056e1a086b489d8db9
Security Audit — socket — carapi