compass-ai

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's stated purpose is coherent with its capabilities, and the install source appears official and proportionate. However, it routes Compass AI access through Membrane's CLI and proxy infrastructure instead of directly to Compass, creating meaningful intermediary trust and credential/data-flow risk. This looks like a legitimate vendor-managed integration, not malware, but the third-party proxy model raises medium security concerns.

Confidence: 88%Severity: 54%
Audit Metadata
Analyzed At
Apr 21, 2026, 11:19 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcompass-ai%2F@4146dae7670d9d274c7e8191e73f5002a28bc4d7