bigml
Warn
Audited by Socket on Apr 21, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's purpose is coherent, and the CLI install source is relatively legitimate, but the integration routes authentication and BigML data through Membrane as an intermediary rather than directly to BigML. That third-party credential and data path, plus mutable CLI installation and remote action generation, creates medium security risk without enough evidence for malware.
Confidence: 85%Severity: 56%
Audit Metadata