instatus

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities generally align, and the CLI comes from a legitimate registry, but the integration is mediated through Membrane rather than directly through Instatus. That intermediary credential and data flow is disclosed and plausibly part of the product design, so this is not confirmed malicious, yet it creates medium security risk through third-party credential custody, indirect API access, and mutable CLI installation.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 22, 2026, 11:25 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Finstatus%2F@df4be1c6120fbfdb52d0bf1e8d075b4a58d7b05e