surveymethods
Warn
Audited by Socket on Apr 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s stated purpose matches its high-level functionality, and the CLI source appears to be an official npm package rather than an obviously malicious payload. However, the integration is not direct: authentication, credential storage/refresh, and API traffic are routed through Membrane as a third-party intermediary, which creates a nontrivial credential and data-flow risk disproportionate to a simple SurveyMethods connector.
Confidence: 84%Severity: 61%
Audit Metadata