mux

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose mostly matches its capabilities, and the CLI comes from npm rather than an obviously rogue source, but the actual data flow is through Membrane as a third-party proxy and credential manager rather than directly to Mux. That makes the footprint broader than a straightforward Mux integration and creates medium security risk from credential forwarding, intermediary access to Mux data, and unpinned CLI execution.

Confidence: 85%Severity: 62%
Audit Metadata
Analyzed At
Apr 30, 2026, 08:02 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmux%2F@346ade3f2e63a5eba4e2159d54165279bb751999
Security Audit — socket — mux