elastic

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly coherent for a Membrane-mediated Elastic integration and uses an official npm-distributed CLI, so it is not overtly malicious. Risk comes from the intermediary data flow through Membrane instead of direct Elastic APIs, global mutable CLI install, and the ability to create/run arbitrary actions against Elastic.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 1, 2026, 01:14 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Felastic%2F@1d257940d8550ac65b6e9642bf094a963496a445
Security Audit — socket — elastic