spotlightr

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the install path is relatively coherent, but the skill's core design routes Spotlightr authentication and API traffic through Membrane rather than directly to Spotlightr. That third-party gateway model is broader than the stated single-service integration and creates meaningful credential and data-flow risk without clear necessity.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Apr 29, 2026, 04:11 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fspotlightr%2F@974eb28ae48617d33bfc41e9c48c9545331398e0
Security Audit — socket — spotlightr