marvel

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's overall purpose is plausible, and the CLI install path is consistent with the publisher, but the core integration is mediated entirely by Membrane rather than direct Marvel APIs. That intermediary model makes credentials and Marvel data flow through a third party, which is a meaningful trust and data-flow risk even without clear signs of malware.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
May 2, 2026, 12:02 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmarvel%2F@040749a20f8359d11ffaa5693c398e291af834b4
Security Audit — socket — marvel