google-address-validation

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s stated purpose broadly matches its capabilities, and the CLI comes from an official npm package rather than an obviously malicious source. However, it routes authentication and API activity through Membrane instead of directly to Google, creating a third-party credential/data intermediary, and it uses unpinned `@latest` installs plus dynamic action creation. This is not confirmed malware, but it carries medium security risk due to proxy-style data flow and elevated trust in external CLI/service infrastructure.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 04:10 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgoogle-address-validation%2F@66e98cdfad560ab943512a440499533a33a1351b
Security Audit — socket — google-address-validation