apify

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly aligned with its stated purpose and uses a plausible official npm-distributed CLI, so it does not look malicious. However, it routes Apify authentication and API traffic through Membrane as an intermediary, expanding trust and data exposure beyond Apify’s native direct API model; that makes the skill medium risk rather than benign.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 08:26 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fapify%2F@3c776a07cfd933bfc58630d031d6cef74e25a529