httpsms

Warn

Audited by Socket on May 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core capability is broadly aligned with an SMS integration and the CLI installer appears to be first-party and officially distributed via npm, so this is not indicative of malware. However, the skill is inconsistent in its upstream identity because it labels HttpSMS while linking to BulkSMS docs, and it routes all access through Membrane rather than directly to the service, creating intermediary data-flow and action-execution risk. Moderate security risk, low malware likelihood.

Confidence: 89%Severity: 54%
Audit Metadata
Analyzed At
May 7, 2026, 11:25 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fhttpsms%2F@48f1e9bbd1009e032e5c533267f81eab53bc1c0b
Security Audit — socket — httpsms