talkspirit

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly coherent with its stated TalkSpirit integration purpose and uses an official npm-distributed Membrane CLI from the same publisher ecosystem, so it is not overtly malicious. The main concern is architectural: authentication and API traffic are routed through Membrane as a third-party intermediary rather than directly to TalkSpirit, creating moderate credential and data-flow risk, compounded by unpinned @latest CLI execution.

Confidence: 87%Severity: 57%
Audit Metadata
Analyzed At
May 1, 2026, 05:10 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftalkspirit%2F@f09dd57c649a68c3ecc64f819e1462bca0f522bf