new-sloth

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is not overtly malicious and uses an official npm-distributed Membrane CLI, but its purpose is weakly substantiated: it cannot describe New Sloth, cites no official New Sloth docs, and routes authentication, connection management, and action execution through Membrane as an intermediary. The main risk is third-party mediation of credentials and data plus dynamic remote action generation, not confirmed malware.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 23, 2026, 12:57 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fnew-sloth%2F@83ae4ee746c23118275efc26d851277f5a069c93