chatsonic

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent in purpose and uses an official npm-distributed Membrane CLI, but it routes Chatsonic authentication and API traffic through Membrane rather than directly to Writesonic. That third-party credential and data brokerage is proportionally riskier than a direct API integration, though not clear evidence of malware.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Mar 14, 2026, 11:42 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fchatsonic%2F@b5837a5aed2e5713e025d925ca38475045e7c6bc