vmware

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and capabilities are broadly aligned, and the CLI comes from an official npm package rather than an unverifiable binary. However, the integration routes authentication, credentials, and VMware API traffic through Membrane instead of VMware directly, creating a meaningful third-party trust and data-flow risk; mutable `@latest` installs add moderate supply-chain risk.

Confidence: 89%Severity: 61%
Audit Metadata
Analyzed At
May 1, 2026, 03:11 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fvmware%2F@8bcf7ff4ed52e98aad6787fa07a50656578ff464
Security Audit — socket — vmware