meistertask

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities mostly match its stated MeisterTask integration purpose, and the CLI install path is a legitimate npm-based distribution from the same vendor ecosystem. However, the actual data flow is mediated by Membrane rather than going directly to official MeisterTask endpoints, so credentials and task data are entrusted to a third-party intermediary. This is disclosed and may be expected for Membrane-based skills, but it is a meaningful trust expansion that raises medium security risk.

Confidence: 87%Severity: 53%
Audit Metadata
Analyzed At
Apr 21, 2026, 08:35 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmeistertask%2F@cf73202533bbbfed188a88ebd4aa30fba2498848