density

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s functionality matches its stated purpose, and the CLI comes from an official-looking same-brand npm package, so this is not overtly malicious. However, it shifts all Density authentication and API traffic through Membrane as an intermediary, and installs an unpinned external CLI that will handle connection setup, credentials, and proxied requests. That makes the data flow and trust model broader than a direct Density integration, creating medium security risk without clear evidence of malware.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 05:41 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdensity%2F@06ba9e5bbb672c21c650c318531eaef7300b2725