formio

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill coherently implements a Membrane-mediated Form.io integration, aligning with its stated purpose to manage Form.io data via pre-built actions and a proxy-authenticated flow. It minimizes local credential exposure by handling auth server-side and routing through Membrane, which is appropriate for a connector-type skill. While the design is broadly sound, there are moderate concerns about explicit handling/documentation of token storage, potential leakage in shared environments, and reliance on Membrane as the sole data path. Overall, it is suspiciously tight on credential visibility rather than overtly malicious; activity appears consistent with a legitimate integration skill when Membrane provides the auth lifecycle and proxying.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 01:53 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fformio%2F@991c2b0ea3cb75027a4ffc4fcdcf6872f6aed543