smartbear

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is coherent with its SmartBear-management purpose and uses an official npm-distributed Membrane CLI, so this is not confirmed malware. However, it routes all SmartBear authentication and data access through Membrane as an intermediary instead of direct official SmartBear APIs, creating meaningful third-party credential and data-flow trust concerns; combined with mutable `@latest` installs, this yields medium security risk.

Confidence: 85%Severity: 57%
Audit Metadata
Analyzed At
May 1, 2026, 05:25 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsmartbear%2F@6ba32c1ecd4302d38ff12bf704198724b9ff68b4
Security Audit — socket — smartbear