elastic

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's capabilities fit Elastic management, and the install path is an official npm package rather than an obvious malware delivery chain. However, the actual data flow is mediated by Membrane, which stores/manages credentials and proxies Elastic requests through a third-party platform; that is disclosed but materially expands trust requirements beyond a direct Elastic integration. Overall this looks coherent but medium-risk due to intermediary credential and data routing plus unpinned CLI execution guidance.

Confidence: 87%Severity: 57%
Audit Metadata
Analyzed At
Apr 21, 2026, 05:11 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Felastic%2F@186fa275ee181564a08e10e585ae9ced6c5ee748