simplekpi

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent as a Membrane-based SimpleKPI integration, and its CLI source appears vendor-consistent and npm-hosted. The main concern is data-flow integrity and credential forwarding: all auth and API access are routed through Membrane instead of directly to SimpleKPI, expanding trust to a third-party intermediary. This is disclosed rather than covert, so it does not look malicious, but it carries medium security risk.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
Apr 28, 2026, 07:40 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsimplekpi%2F@8cad6e3220a2254ca6e755da692391bbd8a0d02b
Security Audit — socket — simplekpi