pickrr

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s overall behavior is mostly aligned with its stated Pickrr-integration purpose, and the CLI comes from an official npm package tied to Membrane. The main concern is data-flow integrity and credential forwarding: all auth and API access are mediated by Membrane rather than direct Pickrr endpoints, which expands trust to a third-party platform and server-side credential storage. This is not overtly malicious, but it is a meaningful security and privacy risk that should be disclosed and approved by users.

Confidence: 87%Severity: 52%
Audit Metadata
Analyzed At
Apr 29, 2026, 03:20 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpickrr%2F@746e2ee00a4677b2a4dab8c51e64b039d821c3cb
Security Audit — socket — pickrr