snatchbot

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is coherent as a Membrane-based SnatchBot connector, and its installer is from an official registry rather than an unverifiable binary. However, it routes authentication and action traffic through Membrane instead of direct SnatchBot APIs, expanding the trust boundary and creating medium security risk from third-party credential/data mediation plus unpinned `@latest` CLI execution.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 30, 2026, 12:53 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsnatchbot%2F@2c2b2190f62816465a090e917dafe879a5a6f2df
Security Audit — socket — snatchbot