burst-sms

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly coherent with its stated Burst SMS integration purpose, and the Membrane CLI comes from an official npm package rather than an unverifiable binary. However, all app access is mediated through Membrane instead of direct Burst SMS APIs, the install is unpinned, and the skill enables externally impactful actions like sending SMS and editing contact data. This is not clearly malicious, but it requires meaningful trust in a third-party platform and should be treated as medium risk.

Confidence: 88%Severity: 52%
Audit Metadata
Analyzed At
Apr 22, 2026, 05:12 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fburst-sms%2F@828ba885d3de8b1fc42c19682d3040310f78fa3d