grist

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly coherent with its stated Grist-integration purpose, and the CLI install source appears legitimate. The main concern is data-flow integrity: Grist authentication and API traffic are mediated by Membrane rather than going directly to Grist, which expands trust to a third party and enables broad data operations. This is not clearly malicious, but it is medium risk because the intermediary model and destructive capabilities deserve explicit trust and approval.

Confidence: 86%Severity: 54%
Audit Metadata
Analyzed At
Apr 23, 2026, 09:09 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgrist%2F@088f8493208cb3d6a53e03b4751a16c87a5cab5f