rapidapi
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is not overt malware and uses an official npm package, but its actual footprint centers on a third-party Membrane CLI that stores tokens and proxies RapidAPI traffic through Membrane rather than using RapidAPI directly. That mismatch between stated purpose and data flow, plus mutable CLI installation, makes the skill higher-risk than a normal vendor-direct API integration.
Confidence: 89%Severity: 64%
Audit Metadata