weweb

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the install path is mostly legitimate, but the skill's core design routes WeWeb authentication and API traffic through Membrane as an intermediary rather than using official WeWeb APIs directly. That third-party credential and data path is the main risk and makes the skill broader than its stated purpose.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
May 8, 2026, 05:00 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fweweb%2F@5792c5cce970673d2c5b9a53a7b82ed99e795db9
Security Audit — socket — weweb