statuscake

Warn

Audited by Socket on May 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose matches StatusCake management, and the install source is an official npm package tied to the publisher ecosystem, so this is not clearly malicious. However, it routes authentication and API operations through Membrane as an intermediary rather than directly to StatusCake, and it installs an unpinned external CLI that handles credentials, creating medium trust and data-flow risk.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
May 6, 2026, 11:51 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fstatuscake%2F@577c576a2cbf42610600f0d81ab28b003b2a2379
Security Audit — socket — statuscake