netlify

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's capabilities match its stated Netlify-management purpose, and the CLI install path is reasonably legitimate via npm. However, all access and authentication are mediated by Membrane rather than direct Netlify APIs, creating a third-party credential/data handling layer and enabling destructive account actions; this is coherent but medium-risk and should be used only with explicit user approval for mutations.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 22, 2026, 11:23 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fnetlify%2F@2cc95681cf4842aa2c5a7a28f0e68924537f7984