bolt

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior is mostly coherent for a Membrane-based integration skill, and the CLI install path appears official and documented. However, the skill has notable purpose ambiguity around what 'Bolt' means and routes API activity and credential handling through Membrane as an intermediary rather than directly to the upstream service, which raises moderate trust and data-flow concerns without clear evidence of malicious intent.

Confidence: 83%Severity: 52%
Audit Metadata
Analyzed At
Apr 21, 2026, 07:12 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbolt%2F@e8233f59c66edc2d06e5eca0ae5521c9b49c1f72