growsurf

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly coherent for GrowSurf management, and its CLI install path appears legitimate. The main risk is architectural: all auth and API traffic are mediated by Membrane rather than going directly to GrowSurf, so credentials and business data flow through a third party with write-capable actions.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 21, 2026, 05:38 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgrowsurf%2F@b4c4343e7fdc874f02b9a0ee1d159b79f14ba819