anonyflow

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill appears coherent and its capabilities align with its stated purpose: it instructs how to use the official Membrane CLI to manage AnonyFlow connections, list and run actions, and proxy requests. There are no direct signs of malicious code, obfuscation, or credential-harvesting tricks in the provided text. Main risks are operational/trust choices rather than active malware: the Membrane proxy will see all request payloads (including sensitive data), installing a third-party CLI creates transitive trust, and allowing an agent to run arbitrary proxied requests could enable destructive actions if the agent acts without explicit user consent. Overall the skill is functionally appropriate but requires the user to trust Membrane and to restrict agent autonomy when performing sensitive operations.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 08:58 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fanonyflow%2F@d272fbb5147b1aa376d9c7f04a1dcb72797c5423