paved

Warn

Audited by Socket on May 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is not overt malware and uses an official same-org npm CLI, but its real footprint is a Membrane integration layer more than a direct Paved skill. Requiring a Membrane account, routing auth and data through Membrane, and using unpinned `@latest` commands make the scope and data flow moderately inconsistent with a straightforward Paved-only integration.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
May 6, 2026, 09:32 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpaved%2F@7d4287df5a13741fcda898eda1fbf14760d0d3aa
Security Audit — socket — paved