specific

Warn

Audited by Socket on May 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The install path is same-vendor and not inherently malicious, but the skill is internally inconsistent: it cannot describe the target app, links unrelated `eval` docs, and routes all credentials and data operations through Membrane rather than clearly documented official app endpoints. The capability set is broader than the stated purpose and the data flow relies on a third-party intermediary.

Confidence: 90%Severity: 72%
Audit Metadata
Analyzed At
May 4, 2026, 06:53 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fspecific%2F@3592ef14ffc7db2557e8b18be7be63ce042e26e8