dashbotio

Warn

Audited by Socket on Apr 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's general purpose matches Dashbot.io operations, and the CLI comes from an official npm source, but the real data flow is through Membrane as an intermediary rather than directly to Dashbot. That third-party proxy model and broad request capability make the footprint less trustworthy than the description implies, despite not showing clear malware behavior.

Confidence: 86%Severity: 62%
Audit Metadata
Analyzed At
Apr 25, 2026, 08:48 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdashbotio%2F@068d08e71ee0eb2881fa43334aecd191d0891b47