npm

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent as a Membrane-based npm integration, and its install source is a verifiable first-party npm package rather than an unknown binary. However, it expands the trust boundary by routing npm auth and data through Membrane instead of official npm endpoints, and uses a mutable `@latest` CLI install. This looks more like a legitimate third-party integration wrapper than malware, but the intermediary credential/data flow makes it medium risk rather than benign.

Confidence: 85%Severity: 52%
Audit Metadata
Analyzed At
May 1, 2026, 07:26 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fnpm%2F@6c80bb0fe4257767dea1052e71f675ec638abfdd
Security Audit — socket — npm