signiflow
Warn
Audited by Socket on Apr 30, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s purpose and capabilities are broadly consistent, and the CLI comes from an official npm package linked to the publisher. The main concern is data-flow integrity: SigniFlow access and credentials are mediated through Membrane rather than direct official SigniFlow APIs, creating a third-party trust dependency. This looks like a legitimate integration pattern, not confirmed malware, but it carries medium security risk due to credential forwarding and intermediary routing.
Confidence: 87%Severity: 56%
Audit Metadata