directus

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core Directus-management purpose is plausible, and the CLI install path appears vendor-consistent and registry-based, but the skill materially expands trust by routing authentication and API traffic through Membrane rather than Directus directly. The main risk is third-party credential/data mediation and arbitrary proxy requests, not confirmed malware.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Apr 24, 2026, 04:28 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdirectus%2F@21be7e451b9228e1c69ff7a29f2085c52cb042ab