plextrac

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose broadly matches its capabilities, and the CLI source appears official, but the actual data flow is agent -> Membrane -> PlexTrac rather than direct PlexTrac API use. Requiring a Membrane account, storing third-party credentials server-side, and routing actions through a separate platform are proportionate to Membrane’s integration model but create a nontrivial trust and privacy boundary; combined with mutable `@latest` installs, this makes the skill medium risk rather than benign.

Confidence: 83%Severity: 56%
Audit Metadata
Analyzed At
May 3, 2026, 12:27 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fplextrac%2F@9f486627dc21485cc6028fb301c9090213d92b4b
Security Audit — socket — plextrac