edapp

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities broadly match its EdApp integration purpose, and the CLI install source appears to be an official same-vendor npm package. The main concern is data-flow integrity: EdApp access is funneled through Membrane's proxy and authenticated CLI rather than directly to EdApp, so account data and auth handling are delegated to an intermediary service. This is disclosed and plausibly legitimate, but it increases trust and privacy risk beyond a direct EdApp API skill.

Confidence: 88%Severity: 53%
Audit Metadata
Analyzed At
Apr 21, 2026, 04:12 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fedapp%2F@5690497e23f9f047ee61da292a054421f3c7c650