commandbar

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly coherent with its stated purpose and uses an official npm package from the same publisher ecosystem, so there is no strong evidence of malware. However, it routes CommandBar access through Membrane as a third-party intermediary, uses mutable `@latest` installs, and enables authenticated remote actions through a proxy, which raises medium security risk even though the overall footprint appears purpose-aligned.

Confidence: 86%Severity: 52%
Audit Metadata
Analyzed At
Apr 29, 2026, 08:43 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcommandbar%2F@0a82f43b190769706465d312fe66e32e73fb5c3a
Security Audit — socket — commandbar