pickrr

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s overall behavior is mostly aligned with its stated Pickrr-integration purpose, and the CLI comes from an official npm package tied to Membrane. The main concern is data-flow integrity and credential forwarding: all auth and API access are mediated by Membrane rather than direct Pickrr endpoints, which expands trust to a third-party platform and server-side credential storage. This is not overtly malicious, but it is a meaningful security and privacy risk that should be disclosed and approved by users.

Confidence: 87%Severity: 52%
Audit Metadata
Analyzed At
Apr 22, 2026, 06:00 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpickrr%2F@ea10609099569b57714ad98aa823afb73f341e22