defastra

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly coherent as a Membrane-hosted Defastra connector, and the CLI comes from an official npm package rather than a raw installer. However, all authentication and API traffic are routed through Membrane instead of directly to Defastra, creating a third-party data and credential handling layer that is broader than a direct integration would require.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 28, 2026, 09:31 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdefastra%2F@954653c4ac22c9b79a2a3dbc70863d98c94b9e5c
Security Audit — socket — defastra