embrace

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose generally matches its capabilities, and the CLI install path is a legitimate npm-distributed developer tool. The main concern is data-flow integrity: Embrace access and authentication are routed through Membrane as an intermediary proxy rather than directly to official Embrace APIs, which broadens trust and exposure. This is not fundamentally malicious, but the third-party gateway design and unpinned `npx @latest` usage make it medium risk rather than benign.

Confidence: 87%Severity: 54%
Audit Metadata
Analyzed At
Apr 23, 2026, 06:53 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fembrace%2F@2ecaf57807c0deacc76cd542d33c26698d84788b