chef

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities mostly align with its stated Chef integration purpose, and the CLI install path appears to be an official npm-distributed tool from the same vendor. The main concern is data-flow integrity: Chef access is mediated through Membrane's connection and proxy layer rather than directly to official Chef APIs, so infrastructure data and auth context pass through a third party. This is not confirmed malware, but it introduces meaningful trust and confidentiality risk beyond a direct Chef integration.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 11:23 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fchef%2F@287eea9e03013a7e83fd46fbe5f1346364f7aa92