html-2-pdf

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align, and the CLI comes from an official registry tied to the publisher, so this is not overt malware. However, it routes authentication, requests, and potentially document contents through Membrane instead of directly to the official HTML 2 PDF API, creating meaningful third-party credential and data-handling risk; the mutable `@latest` global CLI install adds moderate supply-chain risk.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 24, 2026, 01:15 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fhtml-2-pdf%2F@6dc6f4148d3c70dfc729306827bfa2a4b53aadbc