flexitime

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s function is coherent at a high level, but it is not a direct Flexitime integration; it requires installing and trusting Membrane’s CLI and routing authentication/data through Membrane-managed services. Because the install path is official npm and there is no clear payload/exfiltration trick, this is not confirmed malware, but the third-party gateway model and mutable CLI installs make the trust boundary materially broader than the stated Flexitime-only purpose.

Confidence: 82%Severity: 62%
Audit Metadata
Analyzed At
May 5, 2026, 08:58 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fflexitime%2F@19917fe1ca46442ee828493ed20ee455525bfb34
Security Audit — socket — flexitime