piano

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the operational footprint mostly matches a normal Membrane integration skill, with official npm-based CLI install and browser auth, but the documentation is materially inconsistent about what 'Piano' is and routes API access through Membrane as an intermediary. This is not confirmed malware, but the mismatch in purpose and indirect data flow make it riskier than a clean, direct API integration guide.

Confidence: 90%Severity: 52%
Audit Metadata
Analyzed At
Apr 2, 2026, 04:11 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpiano%2F@560da3ff6692dc2b6e9e8dc0e78916aaaa8108af