open-exchange-rates

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The installer itself is relatively benign and consistent with Membrane's docs, but the skill's real footprint is broader than its stated purpose: it makes Open Exchange Rates access depend on a third-party Membrane account, CLI, and proxy rather than the official API directly. That intermediary data flow is the main risk.

Confidence: 85%Severity: 64%
Audit Metadata
Analyzed At
Mar 13, 2026, 10:25 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fopen-exchange-rates%2F@3256d41f62d6a8e3ceb95952ba8801368dff41b0