securitytrails

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent, and the CLI appears to be an official Membrane npm package, so this is not confirmed malware. However, it materially expands trust by routing SecurityTrails authentication and API traffic through Membrane rather than using SecurityTrails’ official direct API flow, and it relies on an unpinned external CLI. That makes the skill medium risk with notable credential/data-flow concerns.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Apr 29, 2026, 10:45 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsecuritytrails%2F@032ed5bf47931f0f9515065a8a17cdf99debc9f5
Security Audit — socket — securitytrails