arive

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Overall, the skill is internally consistent with its stated purpose of enabling Arive integration via the Membrane CLI. It relies on Membrane for authentication and credential management, uses official package sources for installation, and confines API interactions to Membrane-mediated or proxy-based requests. There are no evident malicious behaviors, credential exfiltration, or suspicious data flows beyond standard CLI-based integration practices. Security risk is modest and proportional to the legitimate integration use-case; supply-chain risk is typical for CLI tooling but mitigated by official registries and central credential management.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 08:57 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Farive%2F@d0cb9011357515893079f0813144b4287c60d3c0