imagga

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent as a Membrane-hosted Imagga integration, and the CLI install source appears official. The main concern is data-flow integrity and credential forwarding: the skill routes authentication and API activity through Membrane rather than directly to Imagga, increasing the trust boundary and exposure surface. This is not strong evidence of malware, but it is a meaningful medium-risk intermediary-platform pattern.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 30, 2026, 08:01 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fimagga%2F@146bc60b3e116404ea13237b91f356778e3beda6
Security Audit — socket — imagga