logistia-route-planner

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities mostly match its stated purpose, and the install path appears to use an official npm-distributed CLI. However, the core integration routes authentication, credentials, and API traffic through Membrane rather than directly to Logistia, expanding trust to a third-party control plane. This is disclosed and plausibly legitimate, so it is not malicious, but the combination of unpinned CLI execution and proxy-mediated credential/data flow makes the skill medium risk.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:39 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Flogistia-route-planner%2F@de0f268fff8221888416c39025175e65b6de27a8
Security Audit — socket — logistia-route-planner