slybroadcast

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly coherent with its stated purpose, and the CLI appears to be an official same-vendor npm package, so this is not confirmed malware. However, all access is mediated through Membrane rather than direct Slybroadcast APIs, credentials and activity are entrusted to that intermediary, the install is unpinned (`@latest`), and the skill can generate and execute new actions with real-world messaging consequences. This is a medium-risk third-party integration pattern, not a clearly malicious skill.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 28, 2026, 09:30 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fslybroadcast%2F@e422682a5ced06e3ca55b9d02d6d7caece9c2327
Security Audit — socket — slybroadcast