perplexity

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose is plausible and the install path is an official npm package, so this is not confirmed malware. However, the actual integration is a Membrane-mediated proxy model: authentication, credential storage/refresh, and Perplexity actions are routed through a third-party platform rather than Perplexity's first-party API, which creates meaningful credential-forwarding and data-flow risk beyond the stated 'Perplexity integration' framing.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
May 2, 2026, 05:21 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fperplexity%2F@2b73e5c7e5cedd2bf307f0b888cf020ac1d8a01b
Security Audit — socket — perplexity