pliance

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's stated purpose is coherent, and the CLI comes from an official npm package, but the integration routes authentication and Pliance data through Membrane rather than directly to Pliance. This is a proportional integration pattern, yet it meaningfully expands trust and data exposure to a third-party platform, so risk is medium rather than benign.

Confidence: 87%Severity: 52%
Audit Metadata
Analyzed At
Apr 22, 2026, 01:17 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpliance%2F@f8449b2828e8dbded51d6072c0faa1d4667c35e4