insites

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's capabilities broadly match its stated Insites-integration purpose and the CLI comes from an official npm package, but the design routes authentication and all data operations through Membrane rather than directly to Insites. That third-party credential/data mediation plus unpinned CLI installation and support for destructive actions make this medium risk despite being internally coherent.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 04:10 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Finsites%2F@9201cac5d1a2badec1f39a35b5aa932c63b0d5dc
Security Audit — socket — insites