better-proposals
Warn
Audited by Socket on Apr 21, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's purpose matches Better Proposals management, and the npm-installed CLI appears plausibly legitimate, but the integration is built around Membrane as a mandatory intermediary for auth, requests, and data handling. That third-party credential and data routing is disproportionate compared with direct use of Better Proposals' official API and creates meaningful trust and privacy risk, though it is not confirmed malicious.
Confidence: 86%Severity: 64%
Audit Metadata