marvel

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's overall purpose is plausible, and the CLI install path is consistent with the publisher, but the core integration is mediated entirely by Membrane rather than direct Marvel APIs. That intermediary model makes credentials and Marvel data flow through a third party, which is a meaningful trust and data-flow risk even without clear signs of malware.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 05:40 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmarvel%2F@e1c4d56df0b7d55028b820ec609bb1e8d15d93ef