uptime-robot

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is coherent in purpose and uses an official-looking same-vendor CLI from npm, so it is not overt malware. However, it requires users to trust Membrane as an intermediary for authentication, token refresh, and proxied API calls instead of interacting directly with Uptime Robot, which creates meaningful third-party credential and data-flow risk.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
May 2, 2026, 09:49 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fuptime-robot%2F@7a9262995ba42229160ee1c22ccf1d32da4fcbcc
Security Audit — socket — uptime-robot