appmachine
Warn
Audited by Socket on Mar 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
This skill is a documentation/instruction file for using the Membrane CLI to integrate with Appmachine. It does not contain code that directly reads local secret files, execute remote payloads, or contact suspicious domains. The primary security considerations are supply-chain and trust decisions: installing a third-party global CLI from npm and routing API requests and credentials through Membrane centralizes trust in that service. Those choices are legitimate for this integration but create moderate supply-chain and credential-forwarding risk. There are no strong indicators of obfuscation or active malicious behavior in the provided text.
Confidence: 80%Severity: 75%
Audit Metadata