rocket-chat

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's core function is plausible, and the CLI install path is relatively trustworthy via npm, but the actual data flow is mediated through Membrane rather than Rocket.Chat's official API. That third-party gateway model, combined with server-side credential handling and action creation/execution against external systems, makes the footprint broader than a straightforward Rocket.Chat skill. This is not confirmed malware, but it carries medium security risk and trust-boundary concerns.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Apr 30, 2026, 11:07 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Frocket-chat%2F@ecf16d2e0935296459abc239d0f7fdd9b4d905ec
Security Audit — socket — rocket-chat