nessus

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's high-level purpose is coherent, and the install source is an official npm package from the same publisher, so this is not strong evidence of malware. However, all Nessus access and authentication are routed through Membrane, a third-party intermediary, and the skill encourages unpinned CLI execution plus broad proxying of API requests; that makes the data flow and trust model broader than a direct Nessus integration and raises medium security risk.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 28, 2026, 11:53 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fnessus%2F@b9914a4a2aefb9037bf22ef8854f5ec2f01b9799
Security Audit — socket — nessus