beacon

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior is mostly coherent for a Membrane-hosted Beacon integration, and the CLI comes from an official npm scope tied to the publisher. However, the skill routes Beacon access through Membrane rather than official Beacon endpoints, relies on mutable `@latest` installs, and includes a mismatched Beacon/Estimote docs link that undermines trust. This looks more like a medium-risk third-party integration pattern than confirmed malicious behavior.

Confidence: 86%Severity: 52%
Audit Metadata
Analyzed At
Apr 21, 2026, 10:54 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbeacon%2F@82e259ebeb3a4b8c4ee0b8ad7b69a498f22c0871