shortio

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities match its stated Short.io purpose and the CLI comes from an official npm package, so this is not overt malware. However, all auth and API traffic are funneled through Membrane rather than directly to Short.io, creating a meaningful third-party credential and data-handling trust dependency; combined with unpinned npm execution, this makes the skill medium risk rather than benign.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
May 1, 2026, 10:24 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fshortio%2F@6537a32c778c15a267385fbdc3f3a506580768a0
Security Audit — socket — shortio