mason

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and capabilities mostly align, and the CLI install source is legitimate. However, all Mason access is mediated through Membrane, including arbitrary proxy requests, so data and auth are routed through a third-party intermediary rather than directly to official Mason APIs. This is not clearly malicious, but it introduces medium security risk and warrants caution.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Apr 21, 2026, 08:35 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmason%2F@545b06ffc4207918f8fc854faef6ab3575a34872