nicereply

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core purpose is coherent, and the install path uses an official npm package rather than an unverifiable binary. However, it routes Nicereply access and credentials through the Membrane platform instead of directly to official Nicereply APIs, creating meaningful third-party trust and data-flow expansion; combined with mutable `@latest` installs and dynamic action generation, this is medium risk rather than clearly benign.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 28, 2026, 09:31 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fnicereply%2F@68639599d6638fd78d3e73b3aa604ac1c4e01aef
Security Audit — socket — nicereply