splunk

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent as a Membrane-based integration guide, but it is not a direct Splunk integration. Its main concern is data-flow integrity and credential delegation: Splunk auth and request traffic are routed through Membrane's third-party CLI/service, which is broader and riskier than the stated Splunk purpose alone. Supply-chain risk is moderate-low because the CLI comes from the official npm package, but overall security risk is medium due to intermediary auth and proxying.

Confidence: 85%Severity: 69%
Audit Metadata
Analyzed At
Apr 28, 2026, 12:23 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsplunk%2F@5b4e436d8d4c0f8a734e70c67121379dae4ef8b4
Security Audit — socket — splunk