golioth

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's functionality matches its stated Golioth purpose, and the install path is a normal npm package rather than a black-box binary. However, all authentication, credential refresh, and API access are routed through Membrane, a third-party intermediary, expanding trust and data exposure beyond a direct Golioth integration.

Confidence: 85%Severity: 62%
Audit Metadata
Analyzed At
Apr 28, 2026, 10:04 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgolioth%2F@186cea1aab4ca142c2f592896cdb6741152fec85
Security Audit — socket — golioth