expofp

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and capabilities mostly align, and the CLI comes from an official npm package rather than an unknown installer. The main concern is data-flow integrity: ExpoFP authentication and data access are routed through Membrane's infrastructure, which stores and refreshes credentials server-side, so the skill acts as a third-party broker rather than a direct ExpoFP integration. Combined with unpinned `@latest`/`npx` execution, this makes the skill medium risk but not malicious.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 23, 2026, 09:50 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fexpofp%2F@ae91ce89c4adef68a1a13fd7cd90f8ddf947af1f