golioth
Warn
Audited by Socket on Apr 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's functionality matches its stated Golioth purpose, and the install path is a normal npm package rather than a black-box binary. However, all authentication, credential refresh, and API access are routed through Membrane, a third-party intermediary, expanding trust and data exposure beyond a direct Golioth integration.
Confidence: 85%Severity: 62%
Audit Metadata