signalwire
Warn
Audited by Socket on May 13, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is mostly coherent and uses an official npm-distributed CLI from the stated publisher, so there is no strong malware signal. However, its actual data flow is a Membrane-mediated integration rather than direct SignalWire API usage, which expands trust to a third-party intermediary and makes the skill's SignalWire purpose only partially aligned with its real footprint.
Confidence: 87%Severity: 53%
Audit Metadata