tenderly

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose is coherent, but it relies on a third-party intermediary (Membrane) to authenticate to and access Tenderly rather than using Tenderly's official API directly. The npm-installed CLI appears plausibly official and not an unverifiable binary, so this is not confirmed malware; however, the mediated credential/data flow and unpinned `@latest` install make it a medium-risk skill.

Confidence: 85%Severity: 61%
Audit Metadata
Analyzed At
May 3, 2026, 05:07 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftenderly%2F@e62f1607a3b4765f240d8283e485f7caf70ab7df
Security Audit — socket — tenderly