twelve-data

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent as a Membrane connector guide, but not as a direct Twelve Data integration. Its main risk is data-flow integrity: all access is funneled through Membrane's CLI/service instead of Twelve Data's official API, expanding trust and exposing user activity to an intermediary. The npm install path looks publisher-consistent, so this is not confirmed malware, but the third-party gateway model and unpinned CLI install make the skill medium risk.

Confidence: 84%Severity: 63%
Audit Metadata
Analyzed At
May 3, 2026, 03:20 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftwelve-data%2F@91dddb79d2fe51a016e9b7a37d0f16ae6c880355
Security Audit — socket — twelve-data