grab-your-reviews

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s general purpose is coherent, and the CLI install path is from an official registry, but the data flow is brokered through Membrane as a third-party intermediary rather than a clearly matched Grab Your Reviews API, and the cited official docs appear inconsistent with the product. This is not confirmed malware, but it carries meaningful trust and data-routing risk, plus moderate risk from enabling outbound invitations.

Confidence: 82%Severity: 59%
Audit Metadata
Analyzed At
Apr 30, 2026, 12:08 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgrab-your-reviews%2F@7e40e7eadd68a20f9ce07e6185aadfb25361870e