easy-projects

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose and capabilities mostly align, and the CLI comes from an official npm package rather than an unverified binary. However, all Easy Projects authentication and data access are funneled through Membrane as a third-party intermediary, the install is unpinned (`@latest`), and the skill can create new actions dynamically. This is not clearly malicious, but its trust and data-flow model is broader than a direct Easy Projects integration.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 22, 2026, 02:45 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Feasy-projects%2F@2ac2aff89f7f9f7325b8ffdb8138164df117ccaa