silverfin

Warn

Audited by Socket on May 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the install path is reasonably trustworthy, but the skill's real behavior centers on Membrane as an intermediary for authentication, credential refresh, and API proxying rather than direct Silverfin access. That extra trust layer and generic proxy capability make the data flow broader than the stated purpose suggests.

Confidence: 88%Severity: 62%
Audit Metadata
Analyzed At
May 8, 2026, 07:19 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsilverfin%2F@5aab654bfa58783a9f9b93389276f37c2eed7e2d
Security Audit — socket — silverfin