finch

Warn

Audited by Socket on May 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

This skill is mostly coherent as a Membrane-based Finch integration, but it is not a direct Finch integration: authentication, connections, action discovery, and execution are routed through Membrane. That third-party mediation and the unpinned `@latest` CLI usage make it higher-risk than a simple first-party API skill, though there is no strong evidence of malware or overt credential theft.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
May 6, 2026, 08:53 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ffinch%2F@5829f81e878cae5803093adfeed5dc0fb1f576fe
Security Audit — socket — finch