botconversa

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly coherent for a Membrane-based BotConversa integration and uses an official npm-distributed CLI, so it is not malware-like. Risk comes from intermediary routing through Membrane, credential handling delegated to that service, and the ability to take real-world messaging and record-modification actions.

Confidence: 87%Severity: 52%
Audit Metadata
Analyzed At
Mar 15, 2026, 08:25 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbotconversa%2F@2ff5ae3106b11b9d2f2d1fca5bf5ce947c5b687b