omniconvert

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is internally coherent as a Membrane-based Omniconvert integration, and the CLI comes from an official npm package tied to the publisher. However, all auth and API activity is mediated through Membrane rather than direct Omniconvert endpoints, and the mutable `@latest`/`npx` install pattern adds supply-chain risk. This is not confirmed malware, but it requires trusting a third-party intermediary with credentials and data.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
May 2, 2026, 04:50 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fomniconvert%2F@036202a0536dce4cd5bbdc813a5664152cc85726
Security Audit — socket — omniconvert