mackerel

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's stated purpose is Mackerel integration, but its real footprint is a Membrane-platform integration that routes authentication, actions, and returned data through a third-party intermediary instead of Mackerel's official API. The npm install source looks legitimate, so this is not confirmed malware, but the proxy-style data flow and credential handling are broader than a direct Mackerel skill would need.

Confidence: 85%Severity: 66%
Audit Metadata
Analyzed At
Apr 30, 2026, 12:54 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmackerel%2F@4dc1caa39f00807534243828ef8c10356246bffb
Security Audit — socket — mackerel