moov

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's basic purpose is coherent, and its CLI install path looks legitimate, but it materially expands trust by routing Moov authentication and API traffic through Membrane infrastructure. That intermediary proxy design, combined with payment-capable actions, makes the skill higher risk than a direct Moov integration even without clear evidence of malware.

Confidence: 87%Severity: 64%
Audit Metadata
Analyzed At
Apr 21, 2026, 05:11 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmoov%2F@961136ea7060c32a014c4b1ec2a4cc436a7e3f33