softlayer

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly coherent with its stated purpose and uses an official npm-distributed CLI tied to the same vendor, so it is not overt malware. The main concern is data-flow integrity: SoftLayer authentication and actions are mediated through Membrane rather than official IBM endpoints, creating third-party credential and data exposure plus broad action capability. Overall this is a medium-risk integration skill, not a clearly malicious one.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
May 3, 2026, 04:48 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsoftlayer%2F@1b6979bc8a8325be031336da27494a502819ac22
Security Audit — socket — softlayer