flagsmith

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The install path is relatively normal npm-based tooling, but the skill's main inconsistency is architectural: a Flagsmith integration is implemented as a Membrane-mediated gateway that handles authentication, connections, and action execution server-side. That third-party credential and data routing is not well aligned with a direct Flagsmith skill and creates meaningful trust and data-flow risk, though there is not enough evidence to call it confirmed malware.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
Apr 21, 2026, 11:20 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fflagsmith%2F@73d9622ea49789f54b46101a8f4a5a2774b02042