pushover

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is coherent with its stated purpose, but it routes Pushover access through Membrane rather than the official API, creating a meaningful third-party trust and data-handling risk. Install provenance is moderately trustworthy via npm, and there is no clear malware or hidden payload behavior, but the intermediary credential/data flow makes this medium risk rather than benign.

Confidence: 82%Severity: 56%
Audit Metadata
Analyzed At
May 2, 2026, 11:07 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpushover%2F@6ec481fa1ce233113264eee53f241b887a0a3c4d
Security Audit — socket — pushover