pushbots
Warn
Audited by Socket on May 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s purpose and capabilities mostly align, and the CLI install path is official npm-based rather than a malicious downloader. However, all PushBots interactions are routed through Membrane’s CLI/service, so credentials and data are mediated by a third party instead of the official PushBots API, which raises medium trust and data-flow concerns.
Confidence: 85%Severity: 58%
Audit Metadata