rapidapi

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is not overt malware and uses an official npm package, but its actual footprint centers on a third-party Membrane CLI that stores tokens and proxies RapidAPI traffic through Membrane rather than using RapidAPI directly. That mismatch between stated purpose and data flow, plus mutable CLI installation, makes the skill higher-risk than a normal vendor-direct API integration.

Confidence: 89%Severity: 64%
Audit Metadata
Analyzed At
Sep 16, 2026, 09:03 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Frapidapi%2F@c6bd06b30d0322b7a7b24dd7e54d590c75d2224055372b1339b905a98b9a09af
Security Audit — socket — rapidapi