supernotes

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s functionality is mostly aligned with its purpose, and the CLI install path is from an official npm package tied to the publisher. However, all Supernotes access and token handling are mediated through Membrane rather than direct official Supernotes APIs, adding a third-party trust boundary and credential/data routing layer that is not strictly necessary for this task. This looks more like a managed integration platform than outright malware, but the intermediary architecture raises medium security risk.

Confidence: 85%Severity: 54%
Audit Metadata
Analyzed At
May 1, 2026, 09:11 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsupernotes%2F@d9f1c70af32a946ea4ab4ca0df01b80b02125700
Security Audit — socket — supernotes