flourish

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's stated purpose matches its capabilities, and the CLI comes from an official registry tied to the publisher, so this is not outright malicious. However, it materially expands trust by routing Flourish access and authentication through Membrane, uses unpinned external CLI execution, and encourages a proxy model rather than direct official API calls; that makes the skill medium risk despite being broadly coherent.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 02:51 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fflourish%2F@de5ed5ed82de9627dc7fda7310d8b7636210712e