firstup

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly coherent with its stated Firstup-integration purpose and uses a real same-brand CLI from npm, so this is not strong malware evidence. However, all API access and credential handling are routed through Membrane as an intermediary rather than directly to Firstup, which increases trust and data-flow risk; combined with unpinned `@latest` CLI execution, this makes the skill medium risk rather than benign.

Confidence: 88%Severity: 53%
Audit Metadata
Analyzed At
Apr 30, 2026, 12:53 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ffirstup%2F@0a04878c099a4b732a4c12c7383c2ee8c833b2b9
Security Audit — socket — firstup