pay-with-bolt

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated Bolt integration is implemented by routing auth and data through Membrane, a third-party intermediary, rather than official Bolt APIs. The install source is legitimate npm and there is no clear malware or stealth behavior, but the extra trust placed in Membrane for credentials, connections, and action execution creates medium security risk and weakens data-flow integrity.

Confidence: 86%Severity: 62%
Audit Metadata
Analyzed At
Apr 29, 2026, 04:11 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpay-with-bolt%2F@fb0bd0961713d06c4542556f7cbafc5c40480f4c
Security Audit — socket — pay-with-bolt