unlaunch

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose is plausible, but its actual footprint centers on Membrane as an intermediary for install, authentication, credential storage, and API execution rather than direct Unlaunch access. This is not confirmed malware and the install source is an official npm package, but the indirection, third-party credential mediation, and unpinned CLI execution create medium security risk.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
May 3, 2026, 01:03 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Funlaunch%2F@a719550796ca79d264308cd50c0d07a2410227de
Security Audit — socket — unlaunch