ably-realtime

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is internally coherent as a Membrane-based Ably integration, and the CLI comes from an official npm package rather than an unverifiable binary. However, it materially intermediates both credentials and data through Membrane instead of using Ably's official APIs directly, making the trust and data-flow footprint broader than a simple Ably connector. This is not confirmed malware, but it is a medium-risk third-party gateway pattern with unpinned CLI installation and credential forwarding.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 30, 2026, 03:22 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fably-realtime%2F@6157d1721f06f54ebd2ea8e73436209649ae88a4