practitest

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core function is coherent, and the CLI comes from an official npm package tied to the publisher, so this is not confirmed malware. However, the integration is materially mediated by Membrane rather than direct PractiTest APIs, meaning credentials and PractiTest data are forwarded through a third-party service; combined with mutable `@latest` CLI execution, this makes the skill medium risk.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 10:20 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpractitest%2F@23fca01ea7066bc2c7b36610db8a757a3176df1e
Security Audit — socket — practitest