structurizr

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The install source is mostly legitimate, but the skill’s real behavior is to mediate Structurizr through Membrane: authentication, credential refresh, action execution, and proxy requests all flow through a third-party service. That mismatch between a Structurizr skill and Membrane-centered data paths makes the skill higher risk than its description implies, though not confirmed malware.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Apr 28, 2026, 08:14 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fstructurizr%2F@35f663bf4407e08b08412ebb6623db4150030958
Security Audit — socket — structurizr