q2

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities generally align, and installation uses an official npm package rather than an unverifiable binary. However, all authentication and API traffic are routed through Membrane as a third-party intermediary, which creates meaningful credential and data-flow risk even though it is openly documented and consistent with the skill’s design.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 10:39 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fq2%2F@a007fcdea11038dcf03dbe7d40b05ea9309f0a4a
Security Audit — socket — q2