perspectium

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly match its Perspectium integration purpose, and the CLI comes from an official npm package tied to the same vendor ecosystem. The main concern is data-flow integrity: authentication, credential management, and API traffic are routed through Membrane as an intermediary rather than directly to Perspectium, which expands the trust boundary for enterprise data and access tokens. This is not confirmed malware, but it is a medium-risk integration pattern with notable credential-forwarding and proxying concerns.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 04:54 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fperspectium%2F@e375e09f45ca6f99d9b2e8ea99c5e961cadb690d
Security Audit — socket — perspectium