falcosecurity

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is not overtly malicious and its npm-based CLI install appears vendor-consistent, but its actual footprint is broader than a simple Falco integration guide: authentication, credential handling, and API traffic are delegated to Membrane infrastructure rather than going directly to official Falco endpoints. That third-party credential and data mediation is a real trust and data-flow concern, though it is disclosed and plausibly part of the product's design. Overall this looks like a legitimate integration skill with medium security risk due to proxy-based access and mutable CLI execution examples, not confirmed malware.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 21, 2026, 05:38 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ffalcosecurity%2F@9fc9bd2e2d1136a4021f7fc9dbed5a8ce947dd4a