aspireiq

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This SKILL.md is an integration wrapper that delegates authentication and API calls to the Membrane CLI/proxy. There are no indicators of embedded malware, obfuscated payloads, hardcoded credentials, or instructions to download and execute arbitrary third-party binaries via unsafe channels. The primary security consideration is trust in the Membrane service since all sensitive credentials and proxied request payloads flow through it. If an organization accepts that trust, the skill is reasonable and proportionate for its stated purpose. If not, callers should prefer direct API integration or audit the Membrane CLI source before installation.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 08:58 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Faspireiq%2F@6688ea79ae2f3360fcb3987a461334fb1f560f33