asana

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's capabilities fit its Asana-management purpose, and the CLI comes from an official npm package tied to the same publisher, so this is not overt malware. However, the integration routes authentication and Asana data through Membrane as an intermediary service, adds third-party account dependence, and enables state-changing actions; this makes it medium risk despite generally coherent documentation.

Confidence: 86%Severity: 57%
Audit Metadata
Analyzed At
May 3, 2026, 02:36 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fasana%2F@be1e13081ab349bbd04a1b69735d72be4ae7e500