amilia

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is internally coherent as a Membrane-based connector, and its CLI install path is legitimate. However, it routes Amilia authentication and API traffic through Membrane rather than using Amilia's official API directly, so credentials and data are entrusted to a third-party intermediary beyond what the title alone implies. This is not confirmed malware, but it carries medium risk due to credential forwarding and proxy-mediated data flows.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 22, 2026, 07:46 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Familia%2F@26802949f30ea3449c8a3cb73f084cbeefb52414