testimio

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose is coherent, but it routes Testim access and authentication through Membrane rather than direct official Testim APIs. Install source is relatively trustworthy (official npm package), so this is not overtly malicious; however, the intermediary data flow, extra account requirement, and unpinned CLI execution make the trust footprint broader than a simple Testim integration.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 30, 2026, 10:37 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftestimio%2F@b8161b9ecb33e5321f99079582e000fbbd8a8b22