nocodb

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent as a Membrane-based NocoDB integration, and the CLI install path is official npm rather than an unverifiable binary. However, it routes authentication and NocoDB operations through Membrane instead of official NocoDB APIs, creating a third-party credential/data mediation layer, and it uses unpinned `@latest` installs/execution.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:37 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fnocodb%2F@777b2599c85fd8cbcf9e3ab5fa5e07252eeeea56