polymer

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is not overt malware, and its CLI comes from a plausible official npm source, but the stated purpose is inconsistent with the actual behavior. It presents as a Polymer library skill while really routing authentication and API access through Membrane for a separate service/domain, creating medium risk from purpose mismatch and third-party data flow.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 09:15 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpolymer%2F@63627b63ffc3c0588322b051422b59928bb94e42
Security Audit — socket — polymer