golioth

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is coherent as a Membrane-powered Golioth integration, and the CLI install path is reasonably legitimate via npm. However, it routes all Golioth access and auth handling through Membrane instead of Golioth's official direct APIs, creating a significant third-party data and credential trust boundary that is not inherent to a basic Golioth skill.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
Apr 21, 2026, 10:54 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgolioth%2F@778e4290b40544b4d75f2e49fe5701e2357c397b