spotlightr
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the install path is relatively coherent, but the skill's core design routes Spotlightr authentication and API traffic through Membrane rather than directly to Spotlightr. That third-party gateway model is broader than the stated single-service integration and creates meaningful credential and data-flow risk without clear necessity.
Confidence: 87%Severity: 74%
Audit Metadata