ncscale

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly coherent as a Membrane-based integration and uses an official npm-distributed CLI, so it is not outright malicious. However, all NcScale access is funneled through Membrane's proxy/service, the docs understate local credential handling, one command is unpinned, and the NcScale target appears weakly verifiable; together these make the skill medium risk rather than benign.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Mar 30, 2026, 10:01 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fncscale%2F@63cc1a218650a585775dd3909366095b9098d693