mentionlytics

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities are broadly coherent, and the CLI install path is a legitimate npm package rather than a raw downloader. The main issue is data-flow integrity: it routes Mentionlytics authentication and API activity through Membrane as an intermediary, expanding trust to a third-party platform that stores connections and executes actions on the user’s behalf. This is disclosed and may be legitimate, but it is still a medium-risk integration pattern with unpinned CLI installation and third-party credential handling.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
May 2, 2026, 02:50 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmentionlytics%2F@a41c2059578e2aba9e6f2bcd5c0d80724e64f75f
Security Audit — socket — mentionlytics