flagsmith

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s install path is mostly legitimate, but its actual footprint is a Membrane integration that intermediates Flagsmith authentication and API traffic through Membrane services. That third-party credential/data routing is disproportionate to a plain Flagsmith skill and creates medium security risk even without clear malicious intent.

Confidence: 89%Severity: 66%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:39 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fflagsmith%2F@ae94091b3666253c5b0239e8ee7cf3f074a79cb7