quantil
Warn
Audited by Socket on Apr 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is purpose-aligned and uses an official-looking Membrane CLI from npm, but it routes QUANTIL authentication and API traffic through Membrane’s intermediary service instead of the official QUANTIL API. That third-party credential and data mediation is proportionate to the advertised Membrane integration model, yet still creates medium security risk and weaker data-flow integrity than a direct integration.
Confidence: 86%Severity: 57%
Audit Metadata