firehydrant

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities are mostly aligned, and the CLI comes from an official npm package, so this is not confirmed malware. However, it routes FireHydrant authentication and API traffic through Membrane as a third-party intermediary and uses unpinned `@latest` CLI execution, creating meaningful supply-chain and credential/data-flow risk that exceeds a low-risk direct API integration.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
Apr 29, 2026, 04:20 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ffirehydrant%2F@8d7b4b1de639a0bf037d1a42865319ead5e6ff64
Security Audit — socket — firehydrant