gitea

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities broadly match its Gitea-management purpose, and the CLI install path is from an official registry, so this is not overt malware. However, the integration routes Gitea authentication and API traffic through Membrane, a third-party platform, and requires a Membrane account for a Gitea task; that data-flow indirection and credential custody expansion create a medium security risk even though the behavior appears product-consistent rather than deceptive.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
May 1, 2026, 02:25 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgitea%2F@73f90888f7d63369f811ec0f8e7f9ffbb728264a
Security Audit — socket — gitea