usersketch

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly coherent as a Membrane-hosted integration and uses a legitimate same-org npm CLI, so there is no strong evidence of malware. However, it routes all app interaction through Membrane instead of official service APIs, installs an unpinned global CLI, and has a notable documentation/purpose mismatch between UserSketch and Sketch that makes the integration boundaries unclear.

Confidence: 84%Severity: 53%
Audit Metadata
Analyzed At
May 2, 2026, 02:49 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fusersketch%2F@2cd4814e0af4e6729a2732b6d14fde096525940f
Security Audit — socket — usersketch