promptmateio

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly coherent for a Membrane-published integration and uses an official npm-distributed CLI rather than an unverifiable binary, so this is not strongly indicative of malware. However, the data flow is mediated through Membrane rather than direct Promptmate APIs, Promptmate public API docs are absent, and the proxy/request pattern plus `@latest` usage increase trust and supply-chain risk. Risk is moderate because credentials and API traffic are delegated to a third-party integration platform, but the publisher/tool relationship appears consistent.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 21, 2026, 04:13 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpromptmateio%2F@f14000b0ec14c26920f7b5759a305b9d0b82cd57