gocanvas

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is internally coherent for a Membrane-based GoCanvas integration, and its CLI install path is official npm rather than a suspicious download-execute chain. However, it routes GoCanvas authentication and API traffic through Membrane as a third-party intermediary, expanding trust and exposing user data/credentials to a non-GoCanvas service; this is disclosed but still a medium-risk data-flow concern rather than confirmed malware.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 21, 2026, 04:39 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgocanvas%2F@6b007e80fc55e7df78e7ad0a3c544bd8c1d57b7d