proapis
Warn
Audited by Socket on Apr 21, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s capabilities generally match its stated purpose, and the CLI comes from an official registry with plausible same-vendor ownership. However, all auth and API traffic are funneled through Membrane’s managed connection/proxy layer rather than directly to Proapis, creating a meaningful third-party credential/data-flow risk. The footprint is not fundamentally malicious, but the intermediary architecture and minor documentation inconsistency make it higher risk than a direct official API integration.
Confidence: 83%Severity: 56%
Audit Metadata