gooddata

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose is coherent, and the install source is a legitimate npm package tied to the same product ecosystem, so this is not overt malware. However, it mediates all GoodData access through Membrane rather than official GoodData APIs, forwarding authentication and data to a third-party service, and it relies on mutable `@latest` CLI execution. That makes it a medium-risk integration skill with notable trust and data-flow concerns rather than a benign direct API skill.

Confidence: 85%Severity: 62%
Audit Metadata
Analyzed At
May 1, 2026, 09:13 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgooddata%2F@077e4022e6540b6104a87fa90cdd0402202604a7
Security Audit — socket — gooddata