bright-security

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent in purpose and uses an official npm-distributed Membrane CLI, but it introduces a third-party mediation layer for Bright authentication and API traffic. The main risk is data-flow and credential delegation through Membrane, plus unpinned CLI execution and security-tooling capability; this is not confirmed malware.

Confidence: 89%Severity: 64%
Audit Metadata
Analyzed At
Apr 21, 2026, 06:41 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbright-security%2F@9f5856d594c6304cbb77ceabd64203bfed7a675b