hygraph
Warn
Audited by Socket on Apr 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's capabilities match its Hygraph-management purpose, and the CLI install source appears to be an official Membrane package rather than an ad-hoc payload. However, all authentication and API traffic are funneled through Membrane as an intermediary, creating meaningful credential-forwarding and data-flow risk beyond a direct Hygraph integration.
Confidence: 86%Severity: 56%
Audit Metadata