flyio

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose is coherent and the CLI install path looks official, but the integration is fundamentally mediated by Membrane rather than Fly.io. That means Fly.io auth and organization data flow through a third-party service, and the skill enables impactful infrastructure actions without built-in approval controls. This is not confirmed malware, but it carries meaningful trust and credential-forwarding risk.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
Apr 29, 2026, 04:20 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fflyio%2F@06b3ee5f4432fb1d2286b5f644d6b9f05bd4c997
Security Audit — socket — flyio