chatbase

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is internally coherent as a Membrane-powered Chatbase integration, and its CLI install path is from an official npm package rather than an unverifiable binary. However, all authentication and API traffic are routed through Membrane instead of directly to Chatbase, creating a third-party credential/data mediation layer that is broader than a typical direct API skill. This is not confirmed malicious, but it carries medium security risk due to intermediary data flow and mutable CLI installs.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 10:39 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fchatbase%2F@11fbe5e007424b8a5c32fa7053c975b6a5752d0e
Security Audit — socket — chatbase