ikigai

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align, and the CLI install comes from the official npm registry with publisher-consistent branding. However, all Ikigai access and credential handling are mediated by Membrane’s proxy/service instead of the vendor API directly, creating third-party data exposure and trust concentration. The unpinned global CLI install and mixed Ikigai domain references add medium supply-chain and data-flow risk, but there is no clear evidence of outright malware or credential theft behavior.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
May 1, 2026, 12:07 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fikigai%2F@95947c5074210179d1921c2358343468a8ff167b
Security Audit — socket — ikigai