gist

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the install path is relatively trustworthy, but the skill is internally inconsistent about what 'Gist' means and routes authenticated operations through Membrane as an intermediary. The main concern is purpose/data-flow mismatch: GitHub Gist docs and naming are mixed with Gist CRM actions on `getgist.com`, making the true target unclear and requiring extra trust in Membrane's proxy/auth handling.

Confidence: 88%Severity: 62%
Audit Metadata
Analyzed At
Apr 28, 2026, 10:55 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgist%2F@6b7506c7ba38f5ecda48b829bae01c68d120c7ee