treblle

Warn

Audited by Socket on May 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent and uses an official-looking same-publisher CLI from npm, so it does not look overtly malicious. However, its real function is to route Treblle access and data through Membrane as a third-party intermediary, which adds medium trust and data-flow risk beyond a direct Treblle integration.

Confidence: 85%Severity: 52%
Audit Metadata
Analyzed At
May 15, 2026, 09:15 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftreblle%2F@bd6d6ea100d7c0fb19efaa6379338bf8145e8133
Security Audit — socket — treblle