yuja

Warn

Audited by Socket on May 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities mostly align: it is a YuJa integration guide built around Membrane’s documented CLI and connection model. The main concerns are trust and data-flow related, not clear malware: users must install a third-party CLI, use an unpinned latest version, and route YuJa authentication/data through Membrane rather than directly to YuJa. This is disclosed and plausibly legitimate, but it meaningfully expands credential custody and service trust beyond the named SaaS.

Confidence: 86%Severity: 54%
Audit Metadata
Analyzed At
May 7, 2026, 10:30 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fyuja%2F@4a9ca82b4c71f9d4e474fcde391ec24254f31b05
Security Audit — socket — yuja