charisma

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is internally coherent as a Membrane-based Charisma integration and uses an official npm package rather than an unverifiable binary, so it is not outright malicious. However, its core design routes authentication, action discovery, and Charisma operations through Membrane instead of direct Charisma APIs, creating a third-party credential/data intermediary that raises medium security risk.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 30, 2026, 03:23 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcharisma%2F@661c6ab1be2c110dad392ab976b7dd6ba02a0f1e
Security Audit — socket — charisma