worksnaps
Warn
Audited by Socket on Apr 30, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's purpose matches its capabilities, and the CLI source appears to be the publisher's official npm package, so this is not malware-like. However, all Worksnaps access and credential handling are routed through Membrane as a third-party intermediary, and the skill exposes a broad proxy mechanism plus an unpinned CLI install, making it medium-risk rather than benign.
Confidence: 85%Severity: 52%
Audit Metadata