launchdarkly

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose broadly matches LaunchDarkly management, and the npm-installed CLI is not an obviously malicious installer. However, the integration routes authentication and API traffic through Membrane rather than directly to LaunchDarkly, creating third-party credential/data handling and proxying that is not strictly necessary for the stated purpose. This looks more like a high-trust intermediary integration than malware, but the data-flow integrity and credential-forwarding risks are significant.

Confidence: 84%Severity: 69%
Audit Metadata
Analyzed At
Apr 22, 2026, 03:53 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Flaunchdarkly%2F@87ace864324746c294693ead1397227999069cc5