encharge
Warn
Audited by Socket on Apr 24, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s stated purpose matches Encharge management, and the CLI install path is relatively standard via npm. However, the actual data flow is mediated through Membrane rather than direct Encharge APIs, so credentials and Encharge data are entrusted to a third-party platform; combined with unpinned global CLI installation and dynamic action generation, this makes the skill medium-risk rather than clearly benign.
Confidence: 85%Severity: 56%
Audit Metadata