grab

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's capabilities fit its stated Grab integration purpose, and the CLI source is a legitimate npm package tied to Membrane, not an obviously rogue payload. However, the core data flow routes authentication and API activity through Membrane instead of directly to Grab, and the unpinned `@latest`/`npx` execution path adds supply-chain risk. This looks like a coherent third-party gateway integration, not confirmed malware, but it requires meaningful trust in Membrane as an intermediary.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 28, 2026, 10:29 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgrab%2F@e19e2a09eac066fb3f1d3a669d47045d8b762332
Security Audit — socket — grab