float

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's capabilities mostly match its stated Float integration purpose, and installation comes from an official registry tied to the publisher. The main concern is data-flow integrity and trust expansion: all authenticated Float access is mediated by Membrane, a third-party platform that stores/refreshes credentials server-side and proxies requests, plus the CLI install is unpinned. This is not clearly malicious, but it is medium risk because the integration depends on an intermediary rather than direct official API use.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
May 1, 2026, 11:49 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ffloat%2F@25409c0aa36f0a0d3a8af547f3a5543b1f06dd37
Security Audit — socket — float