appbaseio

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The provided file is a documentation/integration guide with no embedded malicious code. The principal security concerns are operational and supply-chain: (1) centralizing credentials and all proxied request content on Membrane increases risk if Membrane or the CLI is compromised or if retention/logging policies are inappropriate; (2) recommending unpinned global installation of @membranehq/cli introduces a standard npm supply-chain install-time risk. There are no hard-coded secrets, obfuscation, or explicit backdoors in this artifact. Operators should review Membrane's security/retention policies, audit the npm package and its dependencies, consider using local/pinned installs, and avoid sending sensitive secrets in proxied requests unless they trust Membrane's controls.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 08:58 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fappbaseio%2F@b3abf793a7a9783fcc0bdacfbb070bfcc5fc469d