knack

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's basic function matches Knack management, and the Membrane CLI install path appears legitimate, but the real integration path routes authentication and API traffic through Membrane rather than directly to Knack. That third-party credential and request mediation is disproportionate enough to raise medium risk, without clear evidence of confirmed malware.

Confidence: 85%Severity: 64%
Audit Metadata
Analyzed At
Mar 15, 2026, 04:25 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fknack%2F@601ece83df1f5eded556cefe5f14934ec06ea580