wix

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities broadly match its Wix eCommerce purpose, and the CLI install path is same-vendor and official via npm. However, all Wix auth and data access are routed through Membrane rather than direct Wix APIs, creating an intermediary trust boundary and credential/data exposure to a third party. This is disclosed and plausibly legitimate, but it is broader than a direct API integration and warrants caution.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
May 1, 2026, 11:13 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fwix%2F@2d34200251bd0cb03f27002239bfe3b038b35633
Security Audit — socket — wix