metabase

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities are mostly coherent, and the CLI comes from an official npm package rather than an obviously rogue installer. However, all authentication and Metabase API traffic are funneled through Membrane as an intermediary, and the skill explicitly promotes that proxy model instead of direct official Metabase API usage. That third-party credential/data routing plus unpinned `@latest` CLI execution creates moderate security risk even without clear evidence of malware.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 08:44 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmetabase%2F@d6d229c64ff255204fa1c1776b32e77b372d6063
Security Audit — socket — metabase