freshlearn

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose matches Freshlearn administration, and the install path appears to use the vendor’s official npm-distributed CLI, so this is not overt malware. The main concern is architectural: all Freshlearn authentication and data access are routed through Membrane as a third-party intermediary, with an unpinned external CLI and dynamic remote action creation. That footprint is somewhat broader than a direct Freshlearn integration and creates medium security risk, but it remains coherent with the stated product model.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 05:48 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ffreshlearn%2F@a987b3c37a3bbf0bfd879d2e75fe031d57519f6d
Security Audit — socket — freshlearn