replicate

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's core purpose is coherent, and the Membrane CLI appears to be an official npm-distributed tool from the same ecosystem. However, the skill presents itself as a Replicate integration while routing all authentication and API traffic through Membrane, a third-party intermediary that stores and refreshes credentials server-side. That data-flow indirection, plus unpinned CLI execution via `@latest`/`npx`, creates medium risk even without clear malicious intent.

Confidence: 89%Severity: 56%
Audit Metadata
Analyzed At
May 1, 2026, 02:33 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Freplicate%2F@e4352698563b741e97c977e9b722086d22b20d41
Security Audit — socket — replicate