murlist

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly match its stated MurList integration purpose, and the CLI install path is from the official npm package rather than a raw download. The main concern is data-flow integrity: MurList access is mediated through Membrane for authentication and proxy requests, so credentials and API traffic are entrusted to a third-party intermediary instead of going directly to MurList. This is disclosed and plausibly legitimate, so it is not malicious, but the extra trust boundary plus unpinned npm/@latest execution make it medium risk rather than benign.

Confidence: 86%Severity: 52%
Audit Metadata
Analyzed At
Mar 28, 2026, 07:54 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmurlist%2F@bf04832e06c96ef6826ef37e1c07e85b5de99668