cnvrgio

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities broadly match its purpose, and the install source is an official npm package rather than an opaque binary. The main concern is data-flow integrity: Cnvrg.io access and credential handling are routed through Membrane's CLI and proxy infrastructure, creating third-party credential forwarding and intermediary API traffic that exceed a direct Cnvrg.io integration. Risk is moderate rather than malicious because this behavior is disclosed and consistent with the skill's Membrane-centered design.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 21, 2026, 05:38 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcnvrgio%2F@6d91273f1349d6d75cc45df13bfa3a58da318a98