strongdm

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's stated purpose is StrongDM integration, but its real footprint is a Membrane-mediated proxy workflow. The install source is relatively legitimate (official npm package, same-vendor context), so this is not confirmed malware, but routing authentication and StrongDM data through a third-party orchestration service is a notable trust and data-flow mismatch for a service-specific skill.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
May 1, 2026, 12:40 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fstrongdm%2F@2e464aa401ac475c0b29cf5f365f158be0128baa
Security Audit — socket — strongdm