uplisting

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose broadly matches its capabilities, and the CLI install path appears to be the vendor’s official npm distribution. However, all authentication and API interaction are funneled through Membrane rather than directly to Uplisting, creating a third-party credential and data mediation layer that is material to trust and data-flow integrity. This is not confirmed malware, but it carries medium risk due to intermediary routing and unpinned `@latest` CLI execution.

Confidence: 83%Severity: 54%
Audit Metadata
Analyzed At
Apr 30, 2026, 10:37 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fuplisting%2F@967c43d166f546b444eef165f44511187dacf94a
Security Audit — socket — uplisting