orama

Warn

Audited by Socket on May 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's core behavior is coherent, but it intermediates all Orama access through Membrane, so user auth, connection credentials, inputs, and results flow through a third-party service and CLI instead of official Orama APIs. Because the installer is an official npm package from the same vendor, this is not malicious by itself; the main concerns are third-party credential/data mediation and mutable `@latest` installs.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
May 6, 2026, 08:17 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Forama%2F@96298362c3028ea810f5912dddb57a5d4c26310f
Security Audit — socket — orama