roompricegenie

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is coherent as a Membrane-based RoomPriceGenie integration, and the CLI install path is official npm rather than an unverifiable binary. However, it routes authentication and app access through Membrane instead of the official RoomPriceGenie API, expanding trust and exposing user data/credentials to an intermediary platform; combined with an unpinned global @latest install, this makes the skill medium risk rather than benign.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
May 12, 2026, 05:50 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Froompricegenie%2F@2653a74f3617d8fdd3d1eb08dd2b62b1d3459234
Security Audit — socket — roompricegenie