charthop

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent as a ChartHop-via-Membrane integration guide, and the CLI source appears to be an official npm package, so this is not confirmed malware. However, the actual data flow routes authentication, actions, and proxy requests through Membrane rather than directly to ChartHop, creating a meaningful third-party credential/data-handling risk; the unpinned CLI install adds moderate supply-chain risk.

Confidence: 88%Severity: 62%
Audit Metadata
Analyzed At
Apr 28, 2026, 09:31 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcharthop%2F@65bd6fdd4dd899468792ef2873fd9100f58aad76
Security Audit — socket — charthop