statuspage-io

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and capabilities mostly align, and the CLI comes from an official registry rather than an opaque binary. However, the core integration routes authentication and Statuspage operations through Membrane as a third-party intermediary, uses a mutable global `@latest` install, and permits dynamic remote action generation. This is not strong evidence of malware, but it is medium security risk due to intermediary credential/data handling and expanded trust in external platform behavior.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 02:49 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fstatuspage-io%2F@53fbb0b8af18243f7ba71cc2684040b9b4f981e2
Security Audit — socket — statuspage-io