flexitime

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s function is coherent at a high level, but it is not a direct Flexitime integration; it requires installing and trusting Membrane’s CLI and routing authentication/data through Membrane-managed services. Because the install path is official npm and there is no clear payload/exfiltration trick, this is not confirmed malware, but the third-party gateway model and mutable CLI installs make the trust boundary materially broader than the stated Flexitime-only purpose.

Confidence: 82%Severity: 62%
Audit Metadata
Analyzed At
Apr 22, 2026, 06:12 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fflexitime%2F@62226dc998699c5918969171cd22784d79bc3c92