vultr

Warn

Audited by Socket on May 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's capabilities mostly match its stated purpose, and the CLI install path appears to be the publisher's official npm package, so this is not strong evidence of malware. However, the core integration routes Vultr authentication and API activity through Membrane instead of directly to Vultr, creating a third-party credential/data handling layer that is broader than a direct API integration and raises medium security concerns.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
May 10, 2026, 03:00 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fvultr%2F@f2210c65522f781bbeb8ca64aaf232db1b143125
Security Audit — socket — vultr