chatra

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s stated purpose aligns with its capabilities, and the CLI install path appears official and low-risk. The main concern is data-flow integrity: Chatra access is mediated through Membrane, a third-party integration layer that receives auth context and business data, plus the skill enables externally visible actions like sending or editing customer messages. This is not confirmed malware, but it carries meaningful trust and operational risk.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 04:53 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fchatra%2F@850590310d9b4c74d4941f1283c2b0a2e619d78a