chimp-rewriter

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is internally coherent as a Membrane-based Chimp Rewriter integration, and its npm-installed CLI appears publisher-consistent. The main risk is data-flow integrity: Chimp Rewriter credentials and API traffic are intentionally mediated by Membrane rather than going directly to the official Chimp Rewriter API, creating a third-party visibility and credential-broker trust boundary. This is not clearly malicious, but it is a meaningful security risk and broader than a direct-service integration.

Confidence: 84%Severity: 57%
Audit Metadata
Analyzed At
Apr 28, 2026, 07:39 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fchimp-rewriter%2F@7657b78e3e92ef9772ff439c3d931a87dfcc2aa0
Security Audit — socket — chimp-rewriter