nowsecure

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent as a Membrane-based NowSecure integration, and its install path is from an official npm package rather than an unverifiable binary. The main concern is data-flow integrity and credential mediation: instead of using official NowSecure APIs directly, the skill routes authentication and operations through Membrane, a third-party platform, while also allowing dynamic action discovery/creation. This is not confirmed malware, but it meaningfully expands trust beyond NowSecure and uses mutable `@latest` installs.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 21, 2026, 10:05 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fnowsecure%2F@54273e2edb23ea7faf42164209739c3f67fa5861