webmerge

Warn

Audited by Socket on May 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities are mostly aligned, and the CLI install path appears official and documented. The main concern is data-flow integrity: instead of talking to WebMerge directly, the skill routes authentication and operations through Membrane as an intermediary platform, which is a meaningful additional trust boundary. This is not strong evidence of malware, but it is a medium security risk due to third-party credential/data handling and the unpinned CLI install.

Confidence: 87%Severity: 53%
Audit Metadata
Analyzed At
May 7, 2026, 06:56 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fwebmerge%2F@5580ae22ff28ab2595d180ec113ffaa8d6f7fa65