writer

Warn

Audited by Socket on May 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities broadly match its stated purpose, and the CLI appears to come from the same Membrane publisher via npm. The main concern is data-flow and credential centralization: Writer access is mediated through Membrane, so tokens and content are entrusted to a third-party integration layer rather than Writer directly. This is not clear malware, but it is a medium-risk external-platform dependency with unpinned CLI installation and delegated credential handling.

Confidence: 86%Severity: 52%
Audit Metadata
Analyzed At
May 4, 2026, 06:46 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fwriter%2F@57036186df7121ec28e5f2bc6886baa3c7632ae2
Security Audit — socket — writer