warp
Warn
Audited by Socket on Apr 30, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's stated purpose is Warp integration, but its real footprint is a Membrane-mediated integration that handles authentication, connection management, and action execution through a third-party service. Install trust is moderate rather than extreme because the CLI is from npm and brand-consistent, but mutable `@latest` usage and the indirect credential/data flow to Membrane make the overall skill higher risk than a direct official Warp integration.
Confidence: 87%Severity: 68%
Audit Metadata