data247
Warn
Audited by Socket on May 10, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is mostly coherent and uses an official same-org CLI from npm, so it is not overtly malicious. However, it routes Data247 access and authentication through Membrane as an intermediary, uses an unpinned global CLI install, and allows dynamic hosted action creation, which raises medium trust and data-flow concerns beyond a direct API integration.
Confidence: 86%Severity: 56%
Audit Metadata