amazon-api-gateway

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill's instructions and capabilities are internally consistent with its stated purpose: it integrates Amazon API Gateway via the Membrane managed connector and CLI. There is no evidence of obfuscated code, direct credential-harvesting scripts, curl|bash download-execute tricks, or hardcoded secrets in the provided text. The primary security consideration is trust in the Membrane service: authentication tokens, request payloads, and responses are proxied through Membrane, so sensitive data and credential-bearing requests are visible to that third party. Installing the @membranehq/cli is a standard npm install step but introduces typical supply-chain risk associated with third-party CLI tools. Overall, this skill is functionally benign for its purpose but requires user trust in Membrane's security and privacy practices.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 08:56 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Famazon-api-gateway%2F@1fe6047e5e218261e8adebd44be85ec1dccb09b2