schedule-it

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities are broadly aligned, and the CLI comes from an official npm package tied to the same publisher ecosystem. However, all Schedule it authentication and API traffic is funneled through Membrane rather than direct official Schedule it endpoints, creating a meaningful third-party credential and data-handling trust dependency. This looks like a legitimate integration pattern, not confirmed malware, but the proxy-based data flow and credential mediation make it medium risk.

Confidence: 85%Severity: 54%
Audit Metadata
Analyzed At
Apr 30, 2026, 08:13 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fschedule-it%2F@062cc0de9484c716a5fe4c53557a36b29510b06f
Security Audit — socket — schedule-it