leap

Warn

Audited by Socket on May 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is not overtly malicious and uses an official npm-distributed CLI from the same vendor, but its actual footprint is only partially aligned with its stated purpose. It routes authentication and all Leap operations through Membrane as an intermediary, and the documented actions do not match the claimed org/project/user management scope. Main risks are third-party mediation, mutable global install, and dynamic action creation expanding capability beyond the static description.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 11, 2026, 11:27 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fleap%2F@c9ecbbafeb83ce74722c559480c6e6082f517438
Security Audit — socket — leap