easyly

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose broadly matches its capabilities, and installation uses npm rather than a raw download-execute chain, which reduces supply-chain concern. However, all Easyly access is mediated through the Membrane CLI/service instead of direct official Easyly endpoints, creating third-party credential and data-routing exposure that is broader than a simple Easyly integration guide implies. The unpinned global CLI install and partial publisher-name mismatch add moderate trust risk, but there is no clear evidence of malware, exfiltration to known capture endpoints, hidden behavior, or disproportionate local credential/file access.

Confidence: 83%Severity: 58%
Audit Metadata
Analyzed At
Apr 23, 2026, 02:43 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Feasyly%2F@a9bdc8c72bb389c8f0554842ce5b9f4f9cf06808