gosquared

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities mostly align, and the CLI comes from an official npm package tied to the same product ecosystem. However, all GoSquared authentication and data access are routed through Membrane rather than directly to GoSquared, and the skill installs an unpinned third-party CLI that can create and run server-side actions. This is not clearly malicious, but it introduces meaningful trust and credential-forwarding risk beyond a simple direct API integration.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 03:21 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgosquared%2F@91937a16cc4a12eac79f5561997afd8d63518019
Security Audit — socket — gosquared