clientary
Warn
Audited by Socket on Apr 21, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is broadly consistent with its stated purpose and uses an apparently official npm-distributed Membrane CLI, but it routes Clientary authentication and API traffic through Membrane rather than directly to Clientary. This intermediary data flow and credential trust expansion make it medium risk, though not confirmed malicious.
Confidence: 86%Severity: 58%
Audit Metadata