nhost

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly aligned with its stated purpose and uses an official npm-distributed Membrane CLI, so it is not overtly malicious. However, it routes Nhost access, credentials, and API traffic through Membrane rather than official Nhost APIs, adding a third-party trust boundary and moderate data-flow risk.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 2, 2026, 07:11 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fnhost%2F@5f0b695af97bd56c522b13bce9e0fba3f329e67a