shortpixel

Warn

Audited by Socket on May 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's core function is plausible, and the CLI install path is consistent with an official npm-distributed Membrane tool, but the actual data flow is mediated through Membrane rather than directly to ShortPixel. That intermediary trust model, plus unpinned `@latest` installs and server-side credential handling by a third party, makes the skill medium risk rather than benign.

Confidence: 84%Severity: 57%
Audit Metadata
Analyzed At
May 6, 2026, 08:53 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fshortpixel%2F@abb72f0c990d91711fa0e1a5999a2f7ec15d65dc