mx-toolbox

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the install source is legitimate, but the skill's real behavior is to make the user authenticate to and route all Mx Toolbox activity through Membrane as an intermediary. That data-flow design is not fully aligned with a plain Mx Toolbox integration and creates moderate credential and data exposure risk.

Confidence: 85%Severity: 61%
Audit Metadata
Analyzed At
Mar 21, 2026, 01:19 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmx-toolbox%2F@5b1803b01b29a4ea4e1f2e80d94ce54f367eb5b0