plasmic

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly consistent with its stated Plasmic-integration purpose, and the install path uses an official npm package rather than an opaque binary. However, credentials and API traffic are intentionally routed through Membrane as an intermediary, not directly to Plasmic, which creates a meaningful third-party trust and data-flow risk. This looks like a legitimate integration pattern with medium security risk, not confirmed malware.

Confidence: 90%Severity: 58%
Audit Metadata
Analyzed At
May 1, 2026, 07:26 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fplasmic%2F@46ff7a6bdc1c7509d0fdd5a0c01464fd705b7146