oncehub

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's overall purpose and capabilities are coherent for OnceHub integration, and the CLI install path appears to be the publisher's official npm-distributed tool rather than a random payload. However, all authentication and data operations are routed through Membrane as an intermediary rather than directly to OnceHub, and the skill uses unpinned `@latest` CLI execution. This is not confirmed malicious, but it introduces medium trust and data-flow risk that is higher than a direct official API integration.

Confidence: 85%Severity: 52%
Audit Metadata
Analyzed At
Apr 22, 2026, 06:00 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Foncehub%2F@2cb2e84d510e4d7be7db54d4bf57d7e83a5606d8