grafbase

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's capabilities broadly match its purpose, and the CLI install path appears legitimate and publisher-consistent. However, the core integration is mediated through Membrane rather than direct Grafbase APIs, meaning authentication and request data are routed through a third-party proxy/service; this is disclosed and coherent, but materially increases trust and data-flow risk.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Mar 13, 2026, 10:43 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgrafbase%2F@1e47f2e9063cbad01099dfdf2673c7bba70d8619