evenium

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and capabilities broadly align, and the CLI install source appears legitimate and vendor-consistent. The main risk is data-flow integrity: all Evenium access and authentication are mediated by Membrane, including proxy requests, so event data and auth context traverse a third-party platform rather than the official API directly. This is not clearly malicious, but it is a medium-risk integration pattern that expands trust beyond Evenium.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 23, 2026, 03:57 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fevenium%2F@a8bf40b713e07fa265c349a68c731a5365939c56