travis-ci

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated Travis CI purpose matches the exposed capabilities, and the CLI install source appears official and proportionate. The main risk is data-flow integrity: all Travis access and credential handling are routed through Membrane as a third-party intermediary, creating moderate trust and credential-forwarding risk despite otherwise coherent scope.

Confidence: 88%Severity: 57%
Audit Metadata
Analyzed At
May 2, 2026, 11:49 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftravis-ci%2F@6605057c15ffabac04838988ef6c810a152cfa5d
Security Audit — socket — travis-ci