ably
Warn
Audited by Socket on Mar 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
This skill is an instructional integration describing how to use the Membrane CLI to manage Ably connections and proxy API requests. It does not contain executable or obfuscated malicious code. The primary security consideration is the trust/supply-chain relationship: installing the Membrane CLI via npm and routing all Ably requests and credentials through Membrane centralizes sensitive data with a third party. If Membrane (or its npm package) is compromised, credentials or request payloads could be exposed. For sensitive environments, prefer direct, audited integrations or review Membrane's security posture and the @membranehq/cli package before installation.
Confidence: 85%Severity: 75%
Audit Metadata