growth-book

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's core behavior is coherent for a Membrane-based GrowthBook integration, and the CLI source is reasonably trustworthy via npm. However, it introduces a third-party control plane and proxy between the agent and GrowthBook, so credentials and data flow through Membrane rather than directly to official GrowthBook endpoints. This is not clearly malicious, but it creates medium security risk and a nontrivial trust/delegation concern.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 28, 2026, 09:31 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgrowth-book%2F@3f7bca2c477aff4fffc9cbed17e7136813711382
Security Audit — socket — growth-book