polymer

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The install source is relatively trustworthy because the CLI comes from the official npm package and matches Membrane documentation, so this is not strong malware evidence. However, the skill is internally inconsistent: it presents Polymer library documentation while actually instructing the agent to use Membrane’s generic connector/proxy platform, and it routes requests and auth through Membrane infrastructure instead of a clearly identified official Polymer API. That mismatch in purpose and data flow makes the skill suspicious rather than benign.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Apr 23, 2026, 05:17 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpolymer%2F@8784ccbcfab86dfbc8b874b44029dd347129e99e