linkly

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose broadly matches its capabilities, and the CLI comes from an official npm package tied to the publisher, so this is not strongly indicative of malware. However, the integration routes authentication and Linkly operations through Membrane as an intermediary rather than directly to official Linkly APIs, and it relies on mutable `@latest` CLI execution; that makes the trust and data-flow footprint larger than a narrow Linkly-only skill.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
May 3, 2026, 09:52 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Flinkly%2F@b33e4fa77f2d146cc4f0d79f56405d91d9e22c39