seqera

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is purpose-aligned and uses an official npm-delivered CLI, but it routes Seqera access through Membrane as a third-party intermediary rather than directly to Seqera's official API. This is not confirmed malware, but it creates medium security risk due to credential and data handling through an external service plus unpinned CLI installation.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Apr 29, 2026, 07:40 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fseqera%2F@bf8fb2a20c4ff045702eb59c472278730e2fec95
Security Audit — socket — seqera