gathercontent

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's overall purpose is coherent, but its actual data flow is mediated by Membrane rather than direct GatherContent APIs. That intermediary model means credentials and content data are handled server-side by a third party, which is a meaningful trust and privacy expansion beyond a typical direct integration. Install risk is modest because the CLI comes from npm, but the proxy-based architecture keeps overall risk in the medium range.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Apr 28, 2026, 05:26 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgathercontent%2F@753e55dc1b150d19171d2526561b63bfd2c2f103
Security Audit — socket — gathercontent