filebase

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly match its stated purpose, and the CLI is installed from the official npm registry rather than an arbitrary download. However, the data flow is not direct to Filebase: authentication and API access are routed through Membrane’s CLI/service, which means credentials and requests are mediated by a third party. That can be legitimate for an integration platform, but it is broader than a simple Filebase skill and increases trust requirements. Risk is medium due to third-party credential mediation and unpinned CLI installation, not confirmed malware.

Confidence: 85%Severity: 52%
Audit Metadata
Analyzed At
May 3, 2026, 07:11 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ffilebase%2F@5fd0f524bfa2204fe7f4bcd0c14d40234a9ebe2d
Security Audit — socket — filebase