openai
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's purpose is plausible and the npm install source appears official, so this is not malware. However, the skill's OpenAI integration is implemented through Membrane as a third-party proxy/auth layer, meaning OpenAI data and access flow through an intermediary rather than directly to OpenAI; combined with an unpinned global CLI install, this makes the skill medium risk and suspicious rather than benign.
Confidence: 87%Severity: 62%
Audit Metadata