signalfx

Warn

Audited by Socket on May 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent in using Membrane for automation, and the CLI comes from npm, but the core integration routes SignalFx authentication and data through Membrane instead of official SignalFx APIs. That third-party credential/data mediation and forced Membrane account requirement make the data flow higher risk than a direct service integration.

Confidence: 84%Severity: 66%
Audit Metadata
Analyzed At
May 10, 2026, 05:08 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsignalfx%2F@420c74b498ba626f571117c023f15388fa9d7d07
Security Audit — socket — signalfx