grist

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's overall purpose and capabilities are coherent for a Grist integration, and the CLI comes from an official npm package rather than an obviously untrusted source. However, it routes Grist access through Membrane instead of directly to Grist, uses an unpinned third-party CLI that can store credentials locally, and enables destructive remote actions. This looks like a legitimate integration skill with medium security risk rather than malware.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
May 2, 2026, 01:43 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgrist%2F@df7adcc46e0e5c994e31ea674a5bedae6d25972a
Security Audit — socket — grist