riddle-quiz-maker

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly coherent with its stated purpose, and the CLI comes from the official npm registry rather than an obviously rogue source. However, all authentication and Riddle Quiz Maker access are mediated through Membrane, a third-party platform, and the skill encourages dynamic action creation plus unpinned `@latest` CLI execution. This is not confirmed malware, but it carries meaningful trust and account-scope risk due to credential delegation, intermediary data flow, and the ability to perform live account actions.

Confidence: 84%Severity: 53%
Audit Metadata
Analyzed At
Apr 30, 2026, 01:11 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Friddle-quiz-maker%2F@5335edf8d8429df41d9f1467653b7a4e047fbea8
Security Audit — socket — riddle-quiz-maker