softr

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is internally coherent as a Membrane-based Softr integration, and its install source is a real same-brand npm package rather than an obviously malicious payload. However, it materially expands trust by routing authentication and application data through Membrane instead of Softr’s official API directly, and it uses an unpinned external CLI plus remotely generated actions. That makes it higher-risk than a direct official Softr integration, but not clearly malicious.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
May 3, 2026, 02:11 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsoftr%2F@a32d6ed293490ed4d5c3d3015f937da1711299b4
Security Audit — socket — softr