percy

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities are mostly coherent, and the CLI source appears to be the publisher's official npm package. However, all Percy access and credentials flow through Membrane as an intermediary, so users must trust a third-party platform with authentication and API traffic; combined with unpinned @latest CLI execution, this creates medium security risk without clear evidence of malware.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
May 1, 2026, 12:40 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpercy%2F@f5f955bb4f0f1391a66d40343dd08ac317ae83ea
Security Audit — socket — percy