semaphoreci

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's functionality is coherent at a high level, but it is not a direct Semaphore integration: it installs and relies on Membrane's CLI/service, requires a Membrane account, and routes Semaphore actions and proxy requests through Membrane-managed infrastructure. Install provenance looks legitimate via npm and same-org branding, so this is not confirmed malware, but the third-party credential custody and intermediary data flow make the skill materially higher risk than a direct Semaphore client.

Confidence: 85%Severity: 72%
Audit Metadata
Analyzed At
Apr 28, 2026, 10:54 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsemaphoreci%2F@a330b7928ad9aa4ebe07dba4acc378071af6f40d
Security Audit — socket — semaphoreci