sentiance

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core purpose is coherent, and the CLI install path appears to be the vendor’s official npm package, so this is not clearly malicious. However, all authentication and Sentiance data access are funneled through Membrane as a third-party intermediary instead of direct Sentiance APIs, which raises medium trust and data-flow concerns; combined with unpinned CLI installation and remote action generation, the overall risk is moderate rather than benign.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 28, 2026, 10:54 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsentiance%2F@f79b49563624d40c55a5e3aca398240fcb0ac0d2