strapi

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly coherent for Strapi integration and uses an official npm-distributed CLI, so it does not look outright malicious. The main concern is data-flow integrity: all Strapi access and credential handling are funneled through Membrane's intermediary service rather than directly to Strapi, which is a meaningful third-party trust and exposure risk.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 28, 2026, 05:28 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fstrapi%2F@c8ea2c4c67e694317b46ccf731119c9cb087a153
Security Audit — socket — strapi