penneo

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose aligns with its capabilities, and its CLI install path appears consistent with the Membrane publisher via npm. The main concern is data-flow integrity: Penneo access is mediated through Membrane's service/proxy, so user data and authenticated requests do not go directly to Penneo. This is not clearly malicious, but it expands trust to a third-party intermediary and uses an unpinned `npx @latest` pattern, making the overall skill medium risk rather than benign.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Apr 21, 2026, 06:41 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpenneo%2F@ce900c4a7b7c3237489064179275a2873facbe1e