textanywhere

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent, and the CLI source appears to be an official npm-distributed Membrane tool, so this is not outright malicious. However, all TextAnywhere access and credentials are mediated through Membrane’s CLI and proxy rather than direct TextAnywhere APIs, and the use of unpinned `@latest` installs adds supply-chain risk. The footprint is plausible for the stated purpose but introduces a notable third-party trust and data-routing dependency.

Confidence: 87%Severity: 60%
Audit Metadata
Analyzed At
Apr 28, 2026, 03:03 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftextanywhere%2F@5941feda57469b615f4a8da11bee511ef927cdf8