chatbot-builder

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly coherent with its stated Chatbot Builder integration purpose and uses a same-vendor CLI from npm, so it does not look overtly malicious. However, it routes authentication and API traffic through Membrane as an intermediary and enables externally visible actions like messaging, creating moderate trust and data-flow risk beyond a simple direct API integration.

Confidence: 85%Severity: 52%
Audit Metadata
Analyzed At
Apr 29, 2026, 07:44 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fchatbot-builder%2F@b192d0286d7d3da95f22d7363500f08bc833e7e9
Security Audit — socket — chatbot-builder