red-hat

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is coherent as a Membrane-powered Red Hat connector, and its install path is relatively legitimate, so this is not confirmed malware. But the actual data path goes through Membrane rather than official Red Hat APIs, meaning credentials and Red Hat data are mediated by a third-party platform; combined with unpinned CLI execution and dynamic action creation, that makes the skill moderately risky and not a pure direct Red Hat integration.

Confidence: 85%Severity: 52%
Audit Metadata
Analyzed At
Apr 30, 2026, 02:30 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fred-hat%2F@8e626a055057c3021c6c5dcd6c79b8ec31b8ba9d
Security Audit — socket — red-hat