datagma

Warn

Audited by Socket on Apr 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and capabilities are mostly aligned, and the CLI install path appears legitimate via official npm publishing. However, the integration routes Datagma authentication and API traffic through Membrane as an intermediary, which adds medium trust and data-flow risk compared with direct use of Datagma's official API. No clear malware or credential-stealing behavior is shown, but the proxy-based architecture and third-party credential handling make this higher risk than a direct API skill.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 25, 2026, 12:50 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdatagma%2F@ae118c08b6975a2badcce1770bc243aed2fa3502