fountain

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent as a Membrane-based Fountain integration and uses an official npm-published CLI, so it is not malware-like. However, it routes authentication and API access through Membrane rather than directly to Fountain, and it uses mutable @latest installs; that intermediary data flow and trust concentration make the skill medium risk rather than benign.

Confidence: 90%Severity: 54%
Audit Metadata
Analyzed At
Apr 29, 2026, 01:46 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ffountain%2F@f479444e9d2c90f82097a8d3fbc8003be035a879
Security Audit — socket — fountain