chaindesk

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is largely coherent with its stated Chaindesk integration purpose and uses a vendor-documented npm CLI, so it is not overtly malicious. However, it requires a Membrane account, routes authenticated Chaindesk access through Membrane infrastructure, and exposes a broad proxy mechanism, creating medium security risk from third-party credential handling and indirect data flows.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 23, 2026, 11:49 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fchaindesk%2F@a39df11880c5bad39990a063d540f06c21ef5786