reviewsio
Warn
Audited by Socket on May 3, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is coherent as a Membrane-based Reviews.io connector, and the CLI source appears official, but it routes authentication and Reviews.io operations through Membrane instead of directly to Reviews.io. This is a disclosed third-party intermediary pattern with moderate security risk, mainly from credential/data centralization and an unpinned `@latest` CLI install, not clear malware.
Confidence: 84%Severity: 56%
Audit Metadata