centrifuge

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly match its stated purpose, and the CLI install path appears legitimate via npm and official Membrane documentation. The main concern is architectural: Centrifuge access and credentials are mediated through Membrane’s proxy and server-side credential storage rather than direct Centrifuge APIs, creating a third-party trust boundary and credential forwarding risk. This is coherent with the product’s design but higher risk than a direct integration.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 26, 2026, 02:43 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcentrifuge%2F@ecaff66ce7aba7f55677c10d18ae9df11c13d414