bright-security
Warn
Audited by Socket on Apr 21, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is coherent in purpose and uses an official npm-distributed Membrane CLI, but it introduces a third-party mediation layer for Bright authentication and API traffic. The main risk is data-flow and credential delegation through Membrane, plus unpinned CLI execution and security-tooling capability; this is not confirmed malware.
Confidence: 89%Severity: 64%
Audit Metadata