timing

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is internally coherent as a Membrane-based Timing integration, and the CLI comes from an official npm package rather than a raw downloader. However, its actual data flow is a third-party gateway model: authentication, connections, and Timing actions are mediated by Membrane instead of using Timing's official API directly. That expands trust and creates moderate security risk, though there is not enough evidence of confirmed malicious intent.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
May 1, 2026, 09:12 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftiming%2F@4f276f6d3571b703f5070f10ac7558f7732fc4bb
Security Audit — socket — timing