gocanvas

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose broadly matches its capabilities, and the CLI comes from an official npm package rather than an opaque binary. However, the integration is not a direct GoCanvas client: authentication, credential refresh, action execution, and proxy requests all flow through Membrane, creating meaningful third-party credential and data-routing risk. This looks more like a legitimate but higher-trust brokered integration than overtly malicious behavior.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
Apr 30, 2026, 09:15 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgocanvas%2F@b1f404a15aa34656de21cb08532e0e0e6c000d23
Security Audit — socket — gocanvas