devrev

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities are mostly aligned, and the CLI install path appears to be an official npm package from the same publisher ecosystem. The main concern is data-flow integrity: DevRev access is funneled through Membrane’s intermediary service and proxy rather than directly to official DevRev endpoints, so user data and delegated auth are entrusted to a third party. This is not fundamentally incompatible with the stated purpose, but it raises medium security risk and trust-boundary concerns.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 26, 2026, 07:24 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdevrev%2F@5f1064d671133a69833ba2a6fa3c395f69350f79