knowfirst

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent for a Membrane-published KnowFirst integration and uses an official npm-distributed CLI, but its real data flow is through Membrane as a third-party intermediary rather than directly to KnowFirst. That makes the main risk credential and data mediation by an external platform, plus some additional risk from unpinned global CLI install and dynamic action creation.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
Apr 22, 2026, 07:44 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fknowfirst%2F@670e93fe947ef8c0ab7772213aa879f560380db1