hologram

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's stated purpose is Hologram integration, but it requires a third-party Membrane CLI/service to mediate authentication and all API requests. The npm install path itself is relatively normal, so this is not confirmed malware, but the credential and data routing are broader than necessary for a simple Hologram skill and create medium security risk.

Confidence: 87%Severity: 64%
Audit Metadata
Analyzed At
Sep 17, 2026, 10:28 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fhologram%2F@5913395b9f5346faaa4986659c51bd7270bc9d0fb9ea0ffd1fa5ebf8526f3c91
Security Audit — socket — hologram