orama
Warn
Audited by Socket on Apr 22, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is coherent as a Membrane-powered Orama integration, and the install source is an official npm package rather than an unverifiable binary. The main concern is data-flow integrity: Orama operations are routed through Membrane's CLI/proxy and account system instead of directly to Orama APIs, creating intermediary trust and visibility risks that are somewhat broader than the skill title implies.
Confidence: 87%Severity: 54%
Audit Metadata