relavate

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose is plausible, but its actual footprint is a Membrane-mediated integration rather than a direct Relavate client. Install trust is moderate and mostly consistent with the publisher, but the main concern is data and auth routing through Membrane's proxy/service layer plus mutable CLI installs. This is not confirmed malware, but it carries meaningful third-party access and data-flow risk beyond a narrowly scoped Relavate-only skill.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Apr 29, 2026, 09:15 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Frelavate%2F@09e88e1f44a989b0d33303df57fe96bfa72aed98
Security Audit — socket — relavate