escape

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's main behavior is not direct Escape integration but routing authentication and API traffic through Membrane infrastructure. Although the CLI comes from npm and the install path is relatively standard, the third-party proxy design, extra Membrane account requirement, and mismatched documentation create a material credential-forwarding and data-flow risk that is not fully aligned with the skill's stated purpose.

Confidence: 90%Severity: 76%
Audit Metadata
Analyzed At
Apr 2, 2026, 11:50 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fescape%2F@7ffb225c8d722b44dd966c582da8a776a9fc598d