fidel-api

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent in purpose, uses an official npm package from the same vendor, and does not show overt malware or obfuscation. However, it intermediates Fidel access through Membrane infrastructure and CLI-managed connections instead of Fidel’s official direct API flow, creating meaningful credential and data-routing trust concerns. Risk is medium rather than high because the install path is official npm and the behavior is openly documented, but the third-party gateway model is broader than a minimal Fidel API skill.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
Apr 29, 2026, 02:49 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ffidel-api%2F@76fca4e94ca0c7f2fe72eb79280807cb0175738a
Security Audit — socket — fidel-api