hashnode
Fail
Audited by Socket on Mar 12, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The Hashnode Membrane skill presents a coherent and proportionate integration: it relies on Membrane’s centralized authentication and proxy-based Hashnode API access, uses standard package sources (npm), and does not request sensitive credentials directly. Data flows are mediated by Membrane, reducing direct credential exposure. Overall, the footprint is BENIGN with MEDIUM risk due to potential data exposure in outputs and reliance on the Membrane proxy for authentication. No evidence of credential harvesting, malicious binaries, or excessive privileges. Monitor for any unintended data surface in action results and ensure explicit user consent for data access in the agent’s UI.
Confidence: 98%
Audit Metadata