rapid7-insight-platform

Warn

Audited by Socket on May 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is purpose-aligned and uses an official npm package tied to the same publisher, so it does not look malicious. However, it routes authentication and Rapid7 API traffic through Membrane instead of directly to Rapid7, creating meaningful third-party credential and data-flow risk; combined with mutable @latest installs, this makes it medium-risk rather than benign.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 7, 2026, 01:00 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Frapid7-insight-platform%2F@4fd16b94cb62c3d2877199f0b806338422c20028