gender-api

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly coherent and uses an official npm-distributed CLI from the same publisher ecosystem, so it does not show strong signs of malware. However, it routes authentication, requests, and potentially sensitive Gender API data through Membrane rather than directly to the official Gender API endpoints, creating a meaningful intermediary trust and data-flow risk; combined with the unpinned global CLI install, this makes it medium risk rather than benign.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 05:44 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgender-api%2F@f78fbd73278549770093fbb05cb4edd4fbded0ae
Security Audit — socket — gender-api