promptmateio

Warn

Audited by Socket on May 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly coherent with its stated Promptmate.io integration purpose, and the Membrane CLI appears to be an official same-org dependency from npm. However, data access is routed through Membrane as an intermediary, Promptmate.io’s official API behavior is not independently documented here, and the generic proxy/fallback model plus unpinned `@latest` CLI usage increase trust and data-flow risk. This looks more like a high-trust brokered integration than outright malicious behavior.

Confidence: 83%Severity: 56%
Audit Metadata
Analyzed At
May 10, 2026, 04:08 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpromptmateio%2F@fec5c662573f33cb4e49270ffbd909cd1a84e2a4