fastly

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose matches Fastly management, but its actual data flow is through Membrane as a third-party credential and API proxy rather than directly to Fastly. Install provenance is reasonably legitimate via npm, so this is not confirmed malware, but the brokered auth model, mutable CLI install, and ability to perform account-changing actions make the overall risk medium.

Confidence: 86%Severity: 61%
Audit Metadata
Analyzed At
Apr 29, 2026, 04:55 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ffastly%2F@131d10882e699a3b7005a1f6bb14aa2d7635e513
Security Audit — socket — fastly