firmalyzer-iotvas-api

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent as a Membrane-based connector, but not as a direct Firmalyzer API integration. The main concern is data-flow integrity: all auth and API traffic are routed through Membrane's intermediary platform, giving it visibility into requests and responses. Install trust is relatively normal via npm, and there is no clear malware behavior, but the third-party proxy design raises meaningful security and privacy risk.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
Mar 29, 2026, 02:44 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ffirmalyzer-iotvas-api%2F@5bcf90d7a7419a45eeaad21cffe5bd43f1c889b8