eyepopai

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's core behavior is mostly coherent for an EyePop integration, and the CLI comes from an official registry. The main concern is that all authenticated EyePop access is funneled through Membrane's third-party proxy/action layer rather than direct EyePop APIs, combined with mutable CLI execution (`@latest`) and possible local credential storage. This is not confirmed malware, but the data-flow and trust model are broader than the skill description implies.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Apr 23, 2026, 08:24 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Feyepopai%2F@bc194fe819099b42148f92a10db84c1b82e98761