sigma

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's capabilities fit its stated Sigma-integration purpose, and the CLI comes from an official registry, so this is not outright malicious. However, it centralizes authentication, credential refresh, and API proxying through Membrane rather than talking directly to Sigma, creating medium trust and data-flow risk; the unpinned `@latest` CLI install adds supply-chain exposure.

Confidence: 88%Severity: 57%
Audit Metadata
Analyzed At
Apr 30, 2026, 04:08 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsigma%2F@ba91de2f3337ca860e27c9a612ae6e8ed5c08017
Security Audit — socket — sigma