hologram

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is not overtly malicious and its CLI provenance is reasonably consistent with the publisher, but it is not a pure Hologram integration. Its main risk is architectural: all Hologram interactions are mediated by Membrane, a third-party platform that handles auth and action execution, creating moderate data-flow and trust-boundary concerns. Overall classification: SUSPICIOUS due to intermediary routing and broad remote-action scope, not confirmed malware.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 22, 2026, 06:54 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fhologram%2F@85a171fbd41799c55bc96bb22e5b6c5f2b9e2f7c