databowl

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose aligns with Databowl management, and install provenance is relatively credible via the official npm package. The main concern is data-flow integrity: all Databowl access and credentials are mediated by Membrane rather than direct official Databowl APIs, creating a third-party trust and credential-forwarding layer. This looks more like a platform-specific integration wrapper than malware, but it is higher risk than a direct Databowl client.

Confidence: 83%Severity: 57%
Audit Metadata
Analyzed At
Apr 21, 2026, 12:10 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdatabowl%2F@a66b6bec5b3b887d6e496fce18a4f96ccfa9877d