tinybird

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's stated purpose matches its Tinybird-management capabilities, and the CLI comes from an official npm package rather than an opaque binary. However, the integration is mediated through Membrane for authentication, action execution, and API proxying, so Tinybird data and credentials flow through a third-party platform instead of directly to Tinybird. Combined with unpinned `@latest` installs, this creates meaningful trust and data-flow risk even though the behavior is openly documented rather than covert.

Confidence: 85%Severity: 61%
Audit Metadata
Analyzed At
Apr 28, 2026, 05:28 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftinybird%2F@2c86844044a212c12e2ee6ff37f3b6eb245709d4
Security Audit — socket — tinybird