okay

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities generally match its stated purpose, and installation comes from the official npm registry under the same vendor ecosystem, so this is not strong malware evidence. However, all authentication and API access are routed through Membrane rather than directly to Okay's official endpoints, creating a meaningful third-party credential and data mediation risk; combined with an unpinned CLI install, this makes the skill medium risk rather than benign.

Confidence: 89%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 05:41 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fokay%2F@dd24d66a6165357bdddc6cbda04fa2facdf236ca
Security Audit — socket — okay