educateme

Warn

Audited by Socket on May 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s overall purpose is coherent, and the Membrane CLI comes from an official npm package rather than an obviously malicious installer. However, the integration routes authentication, action creation, and EducateMe data through a third-party broker (Membrane) instead of direct official EducateMe APIs, and the description is inconsistent about EducateMe documentation. This is not confirmed malware, but it carries medium security risk due to third-party credential/data mediation, remote action generation, and unpinned CLI installation.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
May 6, 2026, 08:17 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Feducateme%2F@2d2a57e1d3e32fff3d7433b5c93e93a1e8a015f9
Security Audit — socket — educateme