vision6

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s stated purpose matches its Vision6 automation capabilities, and installation via npm is more trustworthy than raw download-execute patterns. However, the core integration is mediated through Membrane rather than directly against official Vision6 APIs, and the skill requires trusting an unpinned external CLI plus a third-party service to handle auth and data flows. This is not clearly malicious, but it is a medium-risk delegated-integration pattern rather than a minimal direct Vision6 skill.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 28, 2026, 04:46 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fvision6%2F@69c88cf54fe44dea80479ce4cd90a8b23a036944
Security Audit — socket — vision6