reward-sciences
Warn
Audited by Socket on Sep 19, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's stated purpose matches its capabilities, and the CLI comes from an official npm package, so this is not outright malicious. However, the skill expands trust by requiring a third-party CLI and routing Reward Sciences authentication and API access through Membrane rather than directly to official Reward Sciences endpoints; that intermediary credential/data flow makes the skill moderately risky.
Confidence: 90%Severity: 56%
Audit Metadata