chatbotkit

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose and capabilities are broadly consistent, and the CLI comes from an official npm package, so this is not overt malware. However, it routes all ChatBotKit access, credentials, and action execution through Membrane as a third-party intermediary rather than ChatBotKit directly, which raises medium risk around data flow integrity and credential custody. Unpinned global CLI installation adds low supply-chain risk.

Confidence: 88%Severity: 62%
Audit Metadata
Analyzed At
Apr 30, 2026, 11:08 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fchatbotkit%2F@919b3544020d0da82e232834f7f833ead7119ed3
Security Audit — socket — chatbotkit