amazon-location-service
Audited by Socket on Mar 4, 2026
1 alert found:
SecurityThis skill is a wrapper/integration guide that instructs the user to use the Membrane CLI to interact with Amazon Location Service. There is no evidence of obfuscated or malicious code embedded in the SKILL.md content. The primary security consideration is that all authentication, request proxying, and credential handling are delegated to a third-party service (Membrane). That design concentrates sensitive data and request/response contents in Membrane's infrastructure — acceptable for many use cases but requiring trust in Membrane's security, privacy, and operational practices. Installing the Membrane CLI from npm is a normal supply-chain operation but carries standard risks of any globally-installed CLI dependency. Overall I find low probability of malware in the provided content, but a moderate privacy/trust risk due to third-party proxying of credentials and requests.