nyckel

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities mostly align, and the CLI comes from an official npm package rather than an obviously malicious source. However, Nyckel authentication and API traffic are brokered through Membrane instead of going directly to Nyckel, creating a third-party credential/data handling boundary that is larger than a direct integration. This looks more like a legitimate but medium-risk proxy-based integration than malware.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 21, 2026, 08:35 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fnyckel%2F@2084029d2e7a495dae076b064d0168f05d00b231