snatchbot
Warn
Audited by Socket on Apr 30, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is coherent as a Membrane-based SnatchBot connector, and its installer is from an official registry rather than an unverifiable binary. However, it routes authentication and action traffic through Membrane instead of direct SnatchBot APIs, expanding the trust boundary and creating medium security risk from third-party credential/data mediation plus unpinned `@latest` CLI execution.
Confidence: 84%Severity: 58%
Audit Metadata