emplifi

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose is coherent, and the CLI comes from an official registry tied to the stated publisher, but all Emplifi authentication and API traffic are funneled through Membrane rather than directly to Emplifi. That third-party mediation is disclosed and plausibly integral to the product, so this is not confirmed malicious, but it creates medium security risk through credential forwarding, proxying, and unpinned CLI execution.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 04:53 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Femplifi%2F@043577b30b167e7df79092e3ceab355abfdc9534
Security Audit — socket — emplifi