impression

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core install path is reasonably legitimate because it uses Membrane's official npm CLI, but the skill's stated purpose does not match its documented actions or target service. It also funnels authentication and API traffic through Membrane as a third-party intermediary, which is broader than a straightforward direct-service integration. The main issue is incoherence and indirect data flow, not confirmed malware.

Confidence: 87%Severity: 64%
Audit Metadata
Analyzed At
Apr 28, 2026, 09:32 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fimpression%2F@1dc8d2ac9f9259a635487b4dc1874646f23ccb34
Security Audit — socket — impression