voiceflow

Warn

Audited by Socket on May 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's core function is coherent, and the install source is an official npm package rather than a rogue binary. However, Voiceflow access is mediated through Membrane's third-party platform and CLI, so authentication, actions, and data flow through an intermediary instead of directly to Voiceflow; combined with unpinned CLI installation, this creates medium security risk despite no clear evidence of outright malware.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
May 16, 2026, 03:39 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fvoiceflow%2F@1fcf6cd1dce45d28e29c27ce21ec5d52c0b38b3a
Security Audit — socket — voiceflow