piano

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The operational behavior mostly matches a Membrane-hosted integration skill and uses an official npm-distributed CLI, so this is not confirmed malware. However, the skill has a major purpose/documentation mismatch and routes authentication and API traffic through Membrane as an intermediary, which makes the footprint broader and less trustworthy than a direct Piano integration.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 10:21 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpiano%2F@e765d7ec1a2c9557e7a6980ff3bc79dd663651a1