budibase

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly coherent for Budibase automation, and its install source is a legitimate npm package from the same publisher. The main concern is data-flow integrity: all Budibase access and credential handling are funneled through Membrane’s third-party service and proxy layer instead of direct official Budibase API usage, which increases trust and exposure requirements beyond a simple Budibase integration.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 24, 2026, 12:55 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbudibase%2F@61e9f1d74a642d88e151e789fe9806c8bde63a97