swell

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose matches its capabilities, and the CLI provenance appears legitimate via official npm/org branding. However, the actual data flow is through Membrane as a third-party intermediary rather than directly to Swell, and the skill encourages exclusive use of that intermediary while using unpinned `@latest` CLI installs. This is not clearly malicious, but it introduces medium security risk through credential/data forwarding and mutable dependency execution.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
May 1, 2026, 12:08 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fswell%2F@2996d6ef28654463ed5bf37b41a7314c89c020cd
Security Audit — socket — swell