46elks

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The document is an integration README/skill description that instructs users to install the official Membrane CLI and to use Membrane to manage authentication and proxy requests to 46elks. There is no executable or obfuscated code, no direct credential-harvesting instructions, and no download-and-execute patterns. The primary security concern is trust concentration: credentials and proxied request payloads are routed through Membrane, and installing a global CLI from npm is a supply-chain trust decision. Overall this is not malicious, but it carries a moderate supply-chain / trust risk because Membrane is an intermediary that will see request contents and hold tokens.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 08:57 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2F46elks%2F@8e1ca2b1182084170c9b5449b096401ec3b19859