nlp-cloud

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is coherent as a Membrane-based integration guide, and its CLI comes from an official npm package rather than an unverifiable binary. However, its actual footprint routes authentication, action execution, and potentially sensitive NLP Cloud data through Membrane instead of NLP Cloud’s official direct API, while using unpinned `@latest` installs and remote platform-defined actions. This is not confirmed malware, but it introduces medium security risk due to intermediary data flow and expanded trust in third-party infrastructure.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
May 2, 2026, 05:21 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fnlp-cloud%2F@4d45d664c85655c67821aa0a38301ad94a7f8f8c
Security Audit — socket — nlp-cloud