copernica

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose and capabilities mostly align, and the CLI install path is a legitimate npm-based same-vendor distribution. The main concern is data-flow integrity: Copernica access is mediated through Membrane’s proxy and credential storage, so a third party sits in the auth and data path. This is disclosed and plausibly part of the product design, so it is not outright malicious, but it increases trust and privacy risk beyond a direct Copernica integration.

Confidence: 89%Severity: 54%
Audit Metadata
Analyzed At
Apr 22, 2026, 03:53 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcopernica%2F@9f7e4db96230c5745ca2e36ede6b6b02451b2edf