tonic

Warn

Audited by Socket on May 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent as a Membrane-based Tonic integration, and the CLI install appears to come from the publisher's official npm package. However, it routes authentication and Tonic interactions through Membrane rather than direct Tonic APIs, creating a third-party credential/data trust dependency; combined with an unpinned global CLI install, this makes the skill medium risk rather than benign.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
May 6, 2026, 04:43 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftonic%2F@8fde796750ca6f1fe98c78d7e13982c19e43d362
Security Audit — socket — tonic