whereby

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's stated purpose fits Whereby automation, and the install source is an official npm package, but it introduces a third-party integration layer that receives authentication and mediates all Whereby access. This is not confirmed malware, but it is a medium-risk trust and data-flow expansion compared with a direct Whereby integration.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 2, 2026, 10:53 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fwhereby%2F@fa71a947735b22ffd0fe53d2e635a53af050254d
Security Audit — socket — whereby