mentionlytics

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's core behavior matches its stated purpose, and the CLI install source is reasonably legitimate via npm. However, the integration is not a simple direct Mentionlytics client: it requires a separate Membrane account, local Membrane auth state, and routes Mentionlytics requests and credentials through Membrane-hosted proxy/auth infrastructure. That intermediary trust boundary is clearly disclosed but increases security risk beyond a direct official API integration.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 23, 2026, 05:58 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmentionlytics%2F@a19db5dcc90412ba1c4639b0d224037efbbba8ca