spiff

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose broadly matches its capabilities, and it avoids asking for raw Spiff credentials by using an interactive OAuth-style Membrane login. However, it requires installing and trusting a third-party CLI plus routing Spiff data through Membrane's proxy/service layer instead of direct official Spiff API access. That intermediary architecture is disproportionate for a simple integration guide and creates medium supply-chain and data-flow risk, though there is no clear evidence of overtly malicious behavior or credential theft instructions.

Confidence: 89%Severity: 58%
Audit Metadata
Analyzed At
Apr 30, 2026, 03:05 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fspiff%2F@183e0804dd11a3d20c911cbb36f65a48ec066fbb
Security Audit — socket — spiff