google-gemini

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's core function is plausible, and the CLI install source is consistent with the publisher, but the actual data flow is not a direct Google Gemini integration. All requests and auth are funneled through Membrane as an intermediary proxy, which is broader trust than the skill title implies and creates meaningful third-party exposure of prompts and connection data.

Confidence: 89%Severity: 61%
Audit Metadata
Analyzed At
Mar 14, 2026, 06:32 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgoogle-gemini%2F@a2ba7c40bb7959c9e115e6182116abd1eca2d860