railsr

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities broadly match its stated Railsr integration purpose, and the CLI comes from an official npm package tied to the publisher. The main concern is data-flow integrity: Railsr authentication and API traffic are mediated by Membrane's platform/proxy instead of going directly to Railsr, creating a third-party trust boundary. This looks like a legitimate integration pattern, not confirmed malware, but it carries medium risk due to intermediary credential and data handling plus unpinned CLI installation.

Confidence: 85%Severity: 57%
Audit Metadata
Analyzed At
Apr 28, 2026, 05:27 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Frailsr%2F@f2d752392b312849a6bee1eb8e7b2f912898e92b
Security Audit — socket — railsr