fountain

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is not overt malware, but its stated Fountain purpose is poorly aligned with the actual footprint. It installs and relies on a third-party CLI, routes auth and API traffic through Membrane instead of clear official Fountain endpoints, and can dynamically create connectors, making the trust and data flow broader than the skill description suggests.

Confidence: 88%Severity: 66%
Audit Metadata
Analyzed At
Sep 20, 2026, 12:30 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ffountain%2F@f2ec77d3746cd0d593c7df7fef4dcdaca4ece532ebf7a96e2efd40a26f6e63f7
Security Audit — socket — fountain