lighthouse

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The main issue is purpose/data-flow inconsistency: the skill claims Google Lighthouse website auditing but exposes project-management actions and routes all authenticated traffic through Membrane as an intermediary. The npm-installed Membrane CLI appears legitimately published, so this is not confirmed malware, but the misleading purpose and proxy-based credential/data handling make the skill medium-high risk.

Confidence: 88%Severity: 64%
Audit Metadata
Analyzed At
Apr 21, 2026, 01:15 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Flighthouse%2F@504e51b84490972e6a3c2bc8209c889df590ebbb