openapi-generator

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is not overtly malicious and uses an official npm package from the same publisher, but its real function is a Membrane-mediated integration rather than direct OpenAPI Generator use. The main risk is data-flow integrity: authenticated requests and credentials are handled through Membrane as an intermediary, which is disclosed but broader than the skill title suggests. Overall this is a coherent vendor-authored integration skill with moderate third-party trust and proxying risk, not confirmed malware.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 30, 2026, 12:53 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fopenapi-generator%2F@7a361bdd8760c702d165a6e799fd1692ea1e5559