siteleaf

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose is coherent, and the CLI comes from an official npm source, but the actual integration is mediated through Membrane rather than direct Siteleaf APIs. That creates medium risk around credential forwarding, third-party data visibility, and proxy-based API access, though there is no strong evidence of malware or concealment.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 07:41 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsiteleaf%2F@9baa83530c6e07c83c1ad02931aff4b3ec05d7db
Security Audit — socket — siteleaf