journeyfront

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly aligned with its stated purpose, but it does not talk to Journeyfront directly; it routes authentication, action generation, and data access through Membrane as an intermediary. The install source is reasonably trustworthy (official npm package), so this is not strong malware evidence, but the third-party credential/data path and mutable `@latest` execution make the overall security risk medium.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 2, 2026, 03:23 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fjourneyfront%2F@6b82ca8c35e992689fb09ddfb72ab3b3bc760c45
Security Audit — socket — journeyfront