dyn

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's behavior is broadly consistent with a Membrane-based Dyn integration, and the CLI comes from npm rather than an opaque installer, so this is not confirmed malware. However, the skill's actual footprint is more about routing Dyn access, prompts, and action execution through Membrane's third-party platform than directly using Dyn, with unpinned `@latest` execution and thin Dyn-specific documentation. The main risk is third-party credential/data mediation and mutable CLI supply chain, not overt malicious behavior.

Confidence: 83%Severity: 56%
Audit Metadata
Analyzed At
May 1, 2026, 12:06 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdyn%2F@f09bff0b5735e7a425be36a00e26cf1570719fcd
Security Audit — socket — dyn