sonix

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's install source is reasonably legitimate, but its core behavior routes Sonix authentication and data through Membrane as an intermediary rather than using Sonix's official API directly. That platform-mediated credential and data flow is broader than the stated Sonix integration purpose and creates meaningful third-party trust and exposure risk, though it is not confirmed malware.

Confidence: 84%Severity: 69%
Audit Metadata
Analyzed At
Apr 29, 2026, 08:33 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsonix%2F@c5f24064744946177064e112664013d25c7eeb59
Security Audit — socket — sonix