mediatoolkit

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align, and the CLI comes from a documented same-org npm package, so this is not confirmed malware. The main risk is architectural: Mediatoolkit authentication and data are routed through Membrane’s CLI/service, creating third-party credential and data exposure, plus mutable `@latest` installs. Overall this is a medium-risk integration skill, not a malicious one.

Confidence: 88%Severity: 57%
Audit Metadata
Analyzed At
May 3, 2026, 10:29 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmediatoolkit%2F@f0f0e83e7d523f61be3207131e505e738ccab255
Security Audit — socket — mediatoolkit