snyk

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent, but it routes authentication and Snyk data through Membrane as an intermediary rather than using Snyk directly. The CLI source appears legitimate and same-vendor via npm, so this is not confirmed malware; the main concern is third-party credential and data mediation plus an unpinned global CLI install.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
May 3, 2026, 05:35 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsnyk%2F@51bdfc6c56e77e4cb7cd79df8bbf28a388e8c9b5
Security Audit — socket — snyk