webmerge
Warn
Audited by Socket on May 7, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's purpose and capabilities are mostly aligned, and the CLI install path appears official and documented. The main concern is data-flow integrity: instead of talking to WebMerge directly, the skill routes authentication and operations through Membrane as an intermediary platform, which is a meaningful additional trust boundary. This is not strong evidence of malware, but it is a medium security risk due to third-party credential/data handling and the unpinned CLI install.
Confidence: 87%Severity: 53%
Audit Metadata