insightsoftware

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose largely matches its capabilities, and installation via the official npm package is coherent. The main concern is data-flow integrity: all Insightsoftware access and auth are funneled through Membrane as an intermediary rather than directly to the official service, which materially increases trust and exposure even though the design is openly documented rather than hidden.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 26, 2026, 12:56 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Finsightsoftware%2F@81d3fae79d32429fe3888e254cdbe1ac07867e43