buildbuddy

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose broadly matches its capabilities, and the CLI install path is a normal npm-based distribution rather than a raw payload. However, the integration is not direct: it requires a Membrane account and routes BuildBuddy access, authentication, and proxy requests through Membrane infrastructure, expanding the trust boundary and exposing BuildBuddy data to an intermediary service. Combined with unpinned CLI execution (`@latest`), this is a medium-risk skill rather than clearly benign.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 21, 2026, 03:36 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbuildbuddy%2F@31bd438e580e77b7dcea8db8e0d6f13f86df49c7