sailthru

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's general purpose is coherent, and the CLI install path is an official npm package, but the core integration routes authentication, credentials, and Sailthru data through Membrane rather than Sailthru's official API. That third-party intermediary model, combined with mutable `@latest` execution and remote action generation, creates medium-high security risk without enough evidence of outright malware.

Confidence: 82%Severity: 72%
Audit Metadata
Analyzed At
Apr 30, 2026, 12:09 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsailthru%2F@dc691bfdb56eae76724357c8aed8fe39d5bae7f8
Security Audit — socket — sailthru