redox

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent and not overtly malicious, but it routes Redox access and potentially sensitive healthcare data through Membrane as an intermediary rather than directly to Redox. The install path is reasonably trustworthy via npm, yet the third-party mediation and mutable CLI version create medium security risk.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 30, 2026, 12:08 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fredox%2F@c2ded622e88561850e4b6f2b53693e5ed1486c1d
Security Audit — socket — redox