fireflies

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly aligned with its stated Fireflies-integration purpose and uses an official npm-distributed CLI, but it introduces a third-party trust boundary: authentication, proxying, and data access are mediated by Membrane rather than going directly to Fireflies' official API. That makes the footprint somewhat broader than a direct Fireflies skill, though the behavior is disclosed and proportionate enough to stop short of malicious.

Confidence: 85%Severity: 52%
Audit Metadata
Analyzed At
Mar 16, 2026, 09:47 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ffireflies%2F@731d341872430b829ff32c7c9e6664cee9c2f050