openai

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose is plausible and the npm install source appears official, so this is not malware. However, the skill's OpenAI integration is implemented through Membrane as a third-party proxy/auth layer, meaning OpenAI data and access flow through an intermediary rather than directly to OpenAI; combined with an unpinned global CLI install, this makes the skill medium risk and suspicious rather than benign.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
Sep 17, 2026, 12:04 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fopenai%2F@5c8001266e4683da6fd585a7535af2a4068fb53bfe8bf6cf38d95d39dda93e33
Security Audit — socket — openai