txt-werk

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's basic function is coherent, and the CLI install path is official npm-based, but the integration depends on a third-party Membrane intermediary for auth and data operations rather than clearly documented TXT Werk first-party endpoints. That mismatch and the weak TXT Werk documentation evidence create moderate trust and data-flow concerns, though not enough to indicate confirmed malware.

Confidence: 83%Severity: 56%
Audit Metadata
Analyzed At
Apr 30, 2026, 12:53 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftxt-werk%2F@c053159c6071e70fdd3298188e04bfae3ba0d102
Security Audit — socket — txt-werk