rewardful

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly coherent with its stated Rewardful integration purpose, and the CLI install path is an official npm package from the same ecosystem. However, all authentication and data access are routed through Membrane as a third-party intermediary rather than directly to Rewardful, and the skill encourages remote action creation/execution using mutable `@latest` tooling. This is not clearly malicious, but it introduces medium trust and data-flow risk beyond a direct API integration.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 2, 2026, 11:50 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Frewardful%2F@8da81b987948f5212f412d66a6b07ffe7ed7f96e
Security Audit — socket — rewardful