launchdarkly

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and capabilities are broadly aligned, and the CLI install path is a normal npm-based distribution rather than a raw download-execute lure. However, all LaunchDarkly access is funneled through Membrane as a third-party intermediary instead of the official LaunchDarkly API, so users must trust Membrane with authentication handling and service data. This is not clearly malicious, but the intermediary data flow and mutable global CLI install make it higher-risk than a direct official integration.

Confidence: 81%Severity: 58%
Audit Metadata
Analyzed At
May 3, 2026, 07:09 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Flaunchdarkly%2F@df4e03ecd62c7657433171fcbcd663e7d32f6ea7
Security Audit — socket — launchdarkly