waiverforever

Warn

Audited by Socket on May 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose aligns with business-data automation, and the CLI source appears to be official/vendor-linked. The main concern is data-flow integrity: WaiverForever access is mediated through Membrane rather than directly through WaiverForever’s official API, creating a third-party trust boundary for credentials and data. Overall this looks more like a legitimate but higher-trust integration layer than outright malware.

Confidence: 87%Severity: 57%
Audit Metadata
Analyzed At
May 7, 2026, 05:43 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fwaiverforever%2F@af7c4cee44332bd927afc9e7692ec156b61a3b68
Security Audit — socket — waiverforever