uk-gov-vehicle-enquiry-api

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s general function matches vehicle-enquiry use, and the CLI comes from an official npm package rather than an obvious malware source. However, the integration is materially proxy-based: authentication, connections, and API actions are routed through Membrane instead of the official DVLA API, creating third-party credential/data exposure and a scope mismatch with the plain-language description of a UK gov API integration.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
May 3, 2026, 01:03 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fuk-gov-vehicle-enquiry-api%2F@832db67aeaa66ff3124eafb802dde472ca0cf216
Security Audit — socket — uk-gov-vehicle-enquiry-api