tatum

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly coherent as a Membrane-based Tatum integration, and the CLI source appears official, so this is not confirmed malware. However, it is not a direct Tatum integration: it routes authentication, credentials, and all Tatum actions through Membrane as an intermediary, while offering high-impact blockchain operations and using a mutable CLI install. The main risk is third-party credential/data handling plus autonomous financial/blockchain actions, not hidden exfiltration or obvious malicious code.

Confidence: 84%Severity: 66%
Audit Metadata
Analyzed At
May 3, 2026, 02:36 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftatum%2F@182622705b3dae6523f95119f954f4b83b9ed76b
Security Audit — socket — tatum