budibase
Warn
Audited by Socket on Apr 24, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is broadly coherent for Budibase automation, and its install source is a legitimate npm package from the same publisher. The main concern is data-flow integrity: all Budibase access and credential handling are funneled through Membrane’s third-party service and proxy layer instead of direct official Budibase API usage, which increases trust and exposure requirements beyond a simple Budibase integration.
Confidence: 87%Severity: 58%
Audit Metadata