iauditor-by-safetyculture

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities broadly match its stated purpose, and the CLI install path appears to be the official Membrane distribution. However, the integration is not a direct SafetyCulture client: it requires trusting Membrane as an intermediary for auth, token refresh, and action execution, and it uses an unpinned global CLI. This is a coherent but higher-trust brokered integration, so the main concerns are third-party credential/data handling and action scope, not confirmed malicious behavior.

Confidence: 87%Severity: 52%
Audit Metadata
Analyzed At
Apr 22, 2026, 04:42 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fiauditor-by-safetyculture%2F@0c276036643306d0282298996c88c9469e75b55c