scaleway

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is internally coherent and uses an official Membrane CLI from npm, so it does not look malicious. However, its actual integration pattern routes Scaleway authentication and API traffic through Membrane as an intermediary, which is broader than a direct service-specific skill and creates moderate credential/data-flow risk; combined with unpinned installs, this makes it suspicious rather than benign.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 11:37 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fscaleway%2F@068f6e05b48fff6a19837b95f13c4fdf9b199294
Security Audit — socket — scaleway