tinfoil-security
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s purpose is plausible, and the CLI install source is relatively legitimate, but the integration depends on a third-party Membrane account that mediates Tinfoil authentication and data access. That intermediary routing, plus AI-driven action creation/execution against a security scanning platform, makes the skill materially riskier than a direct, narrowly scoped Tinfoil integration.
Confidence: 85%Severity: 68%
Audit Metadata