metabase
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's purpose and capabilities are mostly coherent, and the CLI comes from an official npm package rather than an obviously rogue installer. However, all authentication and Metabase API traffic are funneled through Membrane as an intermediary, and the skill explicitly promotes that proxy model instead of direct official Metabase API usage. That third-party credential/data routing plus unpinned `@latest` CLI execution creates moderate security risk even without clear evidence of malware.
Confidence: 87%Severity: 56%
Audit Metadata