better-proposals

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose matches Better Proposals management, and the npm-installed CLI appears plausibly legitimate, but the integration is built around Membrane as a mandatory intermediary for auth, requests, and data handling. That third-party credential and data routing is disproportionate compared with direct use of Better Proposals' official API and creates meaningful trust and privacy risk, though it is not confirmed malicious.

Confidence: 86%Severity: 64%
Audit Metadata
Analyzed At
Apr 21, 2026, 07:45 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbetter-proposals%2F@a482cb25b1830a30190fff008c64d2fedb8ea1af