cyfe

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's core purpose matches its capabilities, and the CLI comes from an official npm package, so this is not outright malicious. However, all Cyfe authentication and API traffic are routed through Membrane instead of directly to Cyfe, creating a third-party credential/data mediation layer that is broader than a direct integration and raises medium security concern.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 28, 2026, 10:29 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcyfe%2F@9a6571653871e816f9af83f5aa23c28f611eae3f
Security Audit — socket — cyfe