thoughtly

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s main capabilities fit its stated purpose, and the CLI install path is from an official registry tied to the publisher. But the skill inaccurately claims Thoughtly lacks public developer docs and routes authentication and data through Membrane as a third-party intermediary, creating a trust and data-flow mismatch that is more concerning than a normal direct integration.

Confidence: 84%Severity: 59%
Audit Metadata
Analyzed At
Apr 28, 2026, 04:22 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fthoughtly%2F@8c2c6b647663b3bc9162a8e1d2f15de44969ec76