hume

Warn

Audited by Socket on Apr 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose broadly matches Hume workflow automation, and the CLI install source is official npm, but the actual integration is mediated by Membrane for auth and API proxying rather than direct Hume API use. That intermediary data flow is a real trust and privacy concern, though not enough to call the skill malicious.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 25, 2026, 01:40 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fhume%2F@339dc4eb8a533147b9b41b496120fd1a762b7186