craftboxx

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly coherent with its stated purpose and uses an official npm-distributed Membrane CLI, so it does not show clear malware behavior. However, it intermediates both credentials and API traffic through Membrane rather than talking directly to Craftboxx, which raises medium trust and data-flow concerns, especially with unpinned `@latest` CLI execution.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 28, 2026, 10:04 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcraftboxx%2F@65225ac7834a097525216466de895091d231c89e
Security Audit — socket — craftboxx