detectify

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose broadly matches its capabilities, but it introduces a third-party control plane (Membrane) between the agent and Detectify, so data and delegated auth flow to an intermediary rather than directly to Detectify. The install path is official npm and not overtly malicious, but the unpinned global CLI install and dynamic action generation add moderate supply-chain and control-scope risk.

Confidence: 83%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 10:39 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdetectify%2F@475cfb58148946357436632316e3be387ab33163