watsonx-ai

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is internally coherent as a Membrane-based WatsonX connector, but its true footprint is broader than a direct WatsonX integration because authentication, connection management, and action execution are all routed through Membrane. Install trust is moderate rather than severe because the CLI comes from npm and appears same-vendor, but the third-party mediation of credentials and data makes this higher risk than a normal direct API skill.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Apr 28, 2026, 11:51 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fwatsonx-ai%2F@17ceb8556a1a70e62570de83a0ba201aa6431317
Security Audit — socket — watsonx-ai