saucelabs

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly coherent with its stated purpose, and the CLI comes from an official npm package tied to the same publisher, so this is not confirmed malware. However, the core design routes Sauce Labs authentication and operations through Membrane as an intermediary rather than official Sauce Labs APIs, and it uses mutable `@latest` installs/execution. That makes the skill medium risk: consistent in purpose, but with notable third-party trust and data-flow concerns.

Confidence: 86%Severity: 57%
Audit Metadata
Analyzed At
May 3, 2026, 07:10 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsaucelabs%2F@e4096c47c11594a53c05c968bd0daae414d14c09
Security Audit — socket — saucelabs