privyid

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities broadly match its stated purpose, and the CLI install path appears to be the vendor’s official npm distribution. However, all authentication and PrivyID interaction are mediated through Membrane rather than direct official PrivyID endpoints, creating a third-party trust and data-routing concern. This is not clearly malicious, but the intermediary architecture and unpinned CLI execution make it higher risk than a direct API integration.

Confidence: 84%Severity: 54%
Audit Metadata
Analyzed At
Apr 23, 2026, 07:13 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fprivyid%2F@32860e1900a3b6f2db523b13c4f71c0c8489c4b0