lmnt

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the main issue is internal inconsistency and indirect data flow. The skill claims to be an LMNT integration but its entity model does not match the referenced LMNT product, and all authenticated traffic is routed through Membrane's proxy rather than directly to official LMNT APIs. The npm-based CLI install is relatively normal, so this is not confirmed malware, but the purpose mismatch plus credential mediation make the skill risky to trust as described.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Mar 13, 2026, 12:49 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Flmnt%2F@7531d9717258272da89a7bec14e49698db33b0bd