warp

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's stated purpose is Warp integration, but its real footprint is a Membrane-mediated integration that handles authentication, connection management, and action execution through a third-party service. Install trust is moderate rather than extreme because the CLI is from npm and brand-consistent, but mutable `@latest` usage and the indirect credential/data flow to Membrane make the overall skill higher risk than a direct official Warp integration.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
Apr 30, 2026, 11:36 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fwarp%2F@dd831e457c3ec76a524494db5e0a4b183602b236
Security Audit — socket — warp