shortpixel
Warn
Audited by Socket on May 6, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's core function is plausible, and the CLI install path is consistent with an official npm-distributed Membrane tool, but the actual data flow is mediated through Membrane rather than directly to ShortPixel. That intermediary trust model, plus unpinned `@latest` installs and server-side credential handling by a third party, makes the skill medium risk rather than benign.
Confidence: 84%Severity: 57%
Audit Metadata