cascade-strategy

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core capability matches the stated purpose, and the CLI install source appears legitimate, so this is not outright malicious. However, the skill routes authentication and app data through Membrane instead of directly to Cascade Strategy, asks the agent to trust a globally installed external CLI, uses an unpinned latest version, and enables remote action generation/execution with write capabilities. Those choices are proportionate but materially increase trust and data-flow risk.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
May 3, 2026, 09:50 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcascade-strategy%2F@5c1f5bd20b2d226654f59e1ab5f48d442101e13b
Security Audit — socket — cascade-strategy