updownio

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is functionally aligned with Updown.io management, and its CLI install path appears publisher-consistent and npm-hosted. The main risk is architectural: it routes authentication and API traffic through Membrane rather than directly to Updown.io, creating a third-party credential/data intermediary. Overall this is suspicious-but-not-malicious, with medium security risk driven by data-flow indirection and credential brokering rather than overt malware behavior.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 28, 2026, 11:41 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fupdownio%2F@2fcc4675c4c558cc0c32ccd15e9bd681baac221d
Security Audit — socket — updownio