edgedb

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's core behavior matches its stated EdgeDB purpose, and the CLI appears to be an official Membrane package, so this is not confirmed malware. However, it routes authentication, credentials, and database operations through Membrane as an intermediary and uses unpinned executable installs, creating a meaningful trust and data-flow risk that is higher than a direct EdgeDB client integration.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 06:11 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fedgedb%2F@aeff0694f5ba00d7f26db0a41fd9611fa135faf4