persistiq

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core capability broadly matches an integration skill, and the Membrane CLI appears to be an official npm-distributed tool rather than a random payload. However, the skill is internally inconsistent because it labels PersistIQ while linking Klenty docs, and it routes authentication and API traffic through Membrane as an intermediary instead of directly to official PersistIQ endpoints. This is more consistent with a generic Membrane connector skill than a narrowly scoped PersistIQ skill, creating medium security risk from third-party credential/data handling and mutable CLI installs.

Confidence: 88%Severity: 61%
Audit Metadata
Analyzed At
Apr 30, 2026, 04:06 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpersistiq%2F@defcdc3143272907ef87511d20738b764f42c216
Security Audit — socket — persistiq