puppet

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is internally coherent as a Puppet integration, and the install source appears official to Membrane rather than a random payload. The main risk is architectural: it requires trusting Membrane's CLI and hosted platform as an intermediary for Puppet authentication and operations, with mutable `@latest` installs and potentially broad action execution against infrastructure systems.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
May 5, 2026, 08:44 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpuppet%2F@d372dae569989d371ee4e5b336af4d941041a14f
Security Audit — socket — puppet