wistia

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly coherent as a Wistia integration, and its CLI comes from an official npm package rather than an unknown binary. The main concern is data-flow integrity: all auth and API traffic is routed through Membrane as an intermediary, plus the install/run steps use unpinned `@latest` versions. That makes it higher risk than a direct Wistia integration, but not fundamentally incompatible with the stated purpose.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
May 1, 2026, 11:42 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fwistia%2F@4e43163c2ae0d1919479a2d0dc9f8f18b5f3d0fc
Security Audit — socket — wistia