envoy

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: installation provenance is mostly legitimate, but the skill has notable purpose inconsistencies and routes Envoy authentication/data through Membrane as a third-party intermediary. The footprint is not fully coherent with the stated purpose, so it carries medium risk despite lacking strong signs of outright malware.

Confidence: 90%Severity: 66%
Audit Metadata
Analyzed At
May 3, 2026, 07:11 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fenvoy%2F@9722d527866baa727a22e8ae4a5b74f42d250735
Security Audit — socket — envoy