envoy

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is not overtly malicious, and its npm-based Membrane CLI install is plausible, but the documentation is internally inconsistent about what 'Envoy' it integrates with and routes all API access through Membrane as an intermediary. Broad proxy capability and tenant-modifying actions are proportionate only if the user explicitly intends Membrane-mediated Envoy administration.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Apr 21, 2026, 06:41 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fenvoy%2F@48375edf7790c822b2df39bdabd5ed5188f07535