amplication

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The Amplication integration skill is conceptually coherent with its stated purpose. It uses a legitimate CLI, relies on user-driven authentication, and routes API calls through a trusted intermediary (Membrane) rather than embedding secrets or executing arbitrary code. No malicious patterns (credential harvesting, hidden data exfiltration, or download-execute chains) are evident. Security risk is moderate due to dependency on Membrane as a credential management layer, but this aligns with the described workflow. Overall verdict: BENIGN with moderate security risk due to intermediary trust boundary.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 08:57 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Famplication%2F@0de65a377acd48424289d1a71e1fcdb567f4d563