sonatype

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose is plausible, and the CLI install path is reasonably legitimate, but the actual integration is mediated by Membrane rather than direct Sonatype APIs. That creates a meaningful third-party trust and data-routing gap: Sonatype auth, requests, and returned data pass through Membrane-managed infrastructure. This is not confirmed malware, but it is higher-risk than a direct vendor integration and should be treated as a medium-risk third-party credential/data proxy skill.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 08:13 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsonatype%2F@d5521115f988c72e5a286b9b065f4a9999da957a
Security Audit — socket — sonatype