vindicia

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly coherent with its stated purpose and uses an official npm-distributed CLI, so it is not outright malicious. However, it routes Vindicia authentication, credentials, and data operations through Membrane as an intermediary rather than directly to official Vindicia APIs, and it supports remote action generation/execution, creating medium trust and data-flow risk.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Apr 30, 2026, 11:08 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fvindicia%2F@6d6071f2d1e0d3f30f3985661fd5d4a1aa915c3f
Security Audit — socket — vindicia