kibana

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly coherent and uses an official-looking npm-distributed CLI from the same vendor, so it is not strongly indicative of malware. However, it shifts Kibana authentication and action execution through Membrane-managed infrastructure, and uses unpinned remote CLI execution paths, creating medium security risk and third-party credential/data exposure beyond direct Kibana use.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 10:21 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fkibana%2F@a2d8ac4166784cf2c982063d716c89f07aaa2cdf
Security Audit — socket — kibana