starshipit
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's capabilities mostly match its purpose, and the install path is an official npm package, so this is not malware-like. However, all authenticated Starshipit access is routed through Membrane rather than directly to Starshipit, creating a meaningful third-party credential and data-flow trust boundary that raises medium security risk.
Confidence: 88%Severity: 56%
Audit Metadata