codeq-natural-language-processing-api

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's stated purpose is Codeq API access, but it routes all authentication and API activity through Membrane instead of Codeq's official endpoints. The npm install path itself looks legitimate, so this is not confirmed malware, but the third-party gateway model and mutable latest-version execution make the data flow and trust boundary broader than the description implies.

Confidence: 87%Severity: 64%
Audit Metadata
Analyzed At
Apr 22, 2026, 01:43 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcodeq-natural-language-processing-api%2F@54fa5a70a460f51b7c414dd13cccb4d5da20024b