pirate-weather
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose is weather access, but the skill actually depends on a third-party orchestration platform that brokers authentication, action generation, and all data flows instead of using Pirate Weather’s official API directly. The install source is reasonably trustworthy (official npm package), so this is not confirmed malware, but the proxy architecture and credential/data routing through Membrane raise medium security concerns.
Confidence: 86%Severity: 57%
Audit Metadata