eyepopai

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent as a Membrane-based integration, and the CLI source appears legitimate, but it routes EyePop authentication and API traffic through Membrane rather than directly to official EyePop endpoints. That intermediary data flow and unpinned CLI install create medium security risk, without clear evidence of malware.

Confidence: 83%Severity: 56%
Audit Metadata
Analyzed At
Apr 28, 2026, 10:54 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Feyepopai%2F@9837c526c2cc0fb9eebe517e09db4cebd5433274
Security Audit — socket — eyepopai