display-video-360
Warn
Audited by Socket on Apr 22, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s capabilities largely match its stated purpose, and the CLI install path is consistent with the publisher. The main risk is architectural: all Display & Video 360 access and credential handling are routed through Membrane, a third-party intermediary, plus the docs suggest an unpinned `npx @latest` command. This looks like a legitimate integration pattern, but it requires broader trust in Membrane than a direct Google API integration and can perform consequential remote actions.
Confidence: 84%Severity: 58%
Audit Metadata