pirate-weather

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is mostly coherent with its stated purpose, and its CLI install path appears first-party and official. The main risk is architectural: it routes Pirate Weather access and authentication through Membrane's intermediary platform instead of using Pirate Weather's official API directly, creating moderate trust and data-flow risk but not strong evidence of malware.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 22, 2026, 04:40 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpirate-weather%2F@e771736272683469d0d2aa72817c955894bae7bc