amplitude

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill manifest documents a benign Amplitude integration that uses the Membrane CLI as a managed connector/proxy. There is no embedded malicious code, no instructions to harvest local credentials, and installs are via standard package channels (npm) and documentation pointing to GitHub. The primary security consideration is intentional: Melbrane (the service) will mediate API calls and manage credentials, so users must trust Membrane with their Amplitude data and tokens. If that third-party trust is acceptable, the skill appears safe. If direct control of credentials or avoidance of a third-party proxy is required, this approach is not appropriate.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 08:58 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Famplitude%2F@2323fc1ada37d5957633750c641d8af7965e2781