pitchly

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities are mostly coherent, and the CLI comes from an official npm package rather than an unknown binary. However, the skill centralizes Pitchly authentication and API traffic through Membrane's intermediary service instead of Pitchly's native API flow, creating meaningful credential-forwarding and data-flow trust risk; combined with unpinned CLI execution, this makes it medium risk rather than benign.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 04:11 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpitchly%2F@c4a997706cedd82ff8310ffb77fe1f3cc808a075