logit-io

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core function is not direct Logit.io access but Logit.io access mediated by Membrane’s CLI and proxy service. The install source is relatively trustworthy (official npm package), and there is no clear malware or credential-stealing code, but the third-party routing of authentication and API traffic is a material data-flow mismatch for a skill presented as a Logit.io integration.

Confidence: 86%Severity: 64%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:56 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Flogit-io%2F@954609be9af620742e39b0764df5dbf7855114ac
Security Audit — socket — logit-io