nhost

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities broadly match its stated purpose, and the CLI install source appears official and registry-based, so this is not strong evidence of malware. However, the integration is fundamentally a Membrane proxy for Nhost: authentication, credential storage/refresh, action discovery, and action execution are all routed through Membrane rather than official Nhost APIs, creating meaningful third-party credential-forwarding and data-flow risk. Overall this is coherent but medium risk due to intermediary trust and unpinned CLI installation.

Confidence: 85%Severity: 61%
Audit Metadata
Analyzed At
May 2, 2026, 02:46 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fnhost%2F@776b4250867c5547771c76fda4d64a722d34bd6b