getblock

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly coherent with its stated GetBlock integration purpose and uses an official npm-distributed Membrane CLI, so there is no strong evidence of malware. However, it introduces a third-party trust boundary by routing GetBlock access through Membrane rather than directly to GetBlock, and it includes an unpinned `npx ...@latest` execution pattern. Risk is moderate due to proxying and delegated credential handling, not because the capability is mismatched to purpose.

Confidence: 88%Severity: 52%
Audit Metadata
Analyzed At
Apr 21, 2026, 08:35 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgetblock%2F@ba7698b72308732c84ee15029c7ba7c9ecb55998