new-sloth

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is not overtly malicious and uses an official npm-distributed Membrane CLI, but its purpose is weakly substantiated: it cannot describe New Sloth, cites no official New Sloth docs, and routes authentication, connection management, and action execution through Membrane as an intermediary. The main risk is third-party mediation of credentials and data plus dynamic remote action generation, not confirmed malware.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 30, 2026, 08:11 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fnew-sloth%2F@c72879815ecd90d268525c047bdd6f013a614074