cubicl

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly coherent and uses an official npm-distributed Membrane CLI, so it is not outright malicious. However, it routes Cubicl authentication and data through Membrane instead of Cubicl's official API, creating an intermediary trust and credential/data handling risk; combined with unpinned `@latest` installs, this makes the skill medium risk rather than benign.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 04:21 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcubicl%2F@cf79af03be16cd55a99025c616c356c8ab649442
Security Audit — socket — cubicl