insided
Warn
Audited by Socket on Apr 30, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is internally coherent as a Membrane-based InSided integration, and its install path uses the official npm registry rather than a raw downloader. However, it requires trusting a third-party CLI and routes authentication and app interactions through Membrane instead of directly to InSided, which creates moderate supply-chain and intermediary data-flow risk disproportionate to a simple direct API integration.
Confidence: 84%Severity: 58%
Audit Metadata