directus
Warn
Audited by Socket on Sep 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is coherent in purpose, but it routes Directus access and credentials through Membrane rather than direct Directus APIs, creating a meaningful third-party trust and data-flow dependency. The npm install path is official and same-org, so this is not confirmed malware, but the proxy-based architecture raises medium security risk.
Confidence: 89%Severity: 58%
Audit Metadata