livekit

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is coherent with its stated purpose and uses an official npm-distributed CLI from the same product family, so it does not look overtly malicious. However, it routes LiveKit authentication and data access through Membrane’s intermediary platform instead of direct official LiveKit APIs, and it uses mutable `@latest` installs/execution. This makes it a moderate trust and data-flow risk rather than benign direct API integration.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 28, 2026, 04:48 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Flivekit%2F@ed2e82edff8ea182a912c2609dac95d651b265b1