imgix

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and core capabilities are mostly coherent, and the CLI comes from an official npm package, so this does not look like overt malware. However, the integration is built around Membrane as a third-party intermediary for authentication, credential refresh, and API proxying rather than direct Imgix access, which materially increases trust and data-flow risk beyond a simple Imgix skill.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 30, 2026, 10:38 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fimgix%2F@abe00ca74df2e1a94b3516287308b40364c63a78