mend

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly coherent as a Membrane-powered Mend integration, and the CLI source appears official, so this is not strong evidence of malware. However, all Mend access is routed through Membrane rather than directly to Mend, and the skill promotes installing and using an unpinned external CLI as the control plane, which creates moderate trust and data-flow risk.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
May 3, 2026, 04:33 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmend%2F@86cf04ae4c272d9f13df6104efa2b6d3ce9ae925