dixa

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly coherent and uses an official npm-distributed Membrane CLI consistent with its stated purpose, so this is not strong evidence of malware. However, all Dixa access and credential handling are routed through Membrane as an intermediary, creating meaningful third-party trust and data-flow risk, and the floating `@latest` install weakens supply-chain hygiene.

Confidence: 85%Severity: 52%
Audit Metadata
Analyzed At
May 1, 2026, 10:50 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdixa%2F@a6fe84d3a09bea5e392ed4a5268f83a57e6ae67e
Security Audit — socket — dixa