insightoai

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly coherent with its stated Insighto.ai integration purpose and uses an official-looking npm CLI, but it routes all access through Membrane as a third-party intermediary and includes high-impact messaging/calling actions. Main risk is trust expansion and proxy-based credential/data handling, not confirmed malware.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 30, 2026, 07:06 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Finsightoai%2F@c237a88bf5d4c18640c5a6b327ff13ba4b3ed3c7