lattice

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's core purpose is coherent, and the CLI install source appears to be an official Membrane npm package rather than an unknown payload. However, all Lattice access is mediated through Membrane's third-party service and proxy layer, so credentials and business data do not flow directly to Lattice. That indirect data path is openly documented and may be legitimate for this platform, but it materially increases trust and privacy risk compared with a direct official API integration.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 2, 2026, 05:09 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Flattice%2F@1e5ab9cdfe9b1f8b12c4bef4c05bc5c4420ea3a3