float

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's capabilities mostly match its stated Float integration purpose, and installation comes from an official registry tied to the publisher. The main concern is data-flow integrity and trust expansion: all authenticated Float access is mediated by Membrane, a third-party platform that stores/refreshes credentials server-side and proxies requests, plus the CLI install is unpinned. This is not clearly malicious, but it is medium risk because the integration depends on an intermediary rather than direct official API use.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
May 1, 2026, 11:49 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ffloat%2F@25409c0aa36f0a0d3a8af547f3a5543b1f06dd37