cockroachdb

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly coherent as a Membrane-based CockroachDB integration, but its real footprint is wider than the title implies because all auth and data access are mediated through Membrane and it supports arbitrary proxied requests. Install trust is moderate rather than high-risk because the CLI comes from npm, but `@latest`/`npx` keep the execution path mutable.

Confidence: 82%Severity: 52%
Audit Metadata
Analyzed At
Apr 29, 2026, 04:20 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcockroachdb%2F@154e0ef84edc344ece3cd72929ef9c5ed1b04390