flare

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s behavior is broadly consistent with its stated purpose, but it routes all Flare access through the Membrane CLI/service rather than Flare directly, uses mutable npm execution, and relies on remote action generation. This is not clearly malicious, but it introduces medium trust and data-flow risk through a third-party intermediary.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 1, 2026, 06:13 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fflare%2F@df45a8f88881139a7fb17641ecd274a79bf5e604
Security Audit — socket — flare