dixa
Warn
Audited by Socket on May 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is mostly coherent and uses an official npm-distributed Membrane CLI consistent with its stated purpose, so this is not strong evidence of malware. However, all Dixa access and credential handling are routed through Membrane as an intermediary, creating meaningful third-party trust and data-flow risk, and the floating `@latest` install weakens supply-chain hygiene.
Confidence: 85%Severity: 52%
Audit Metadata