publisherkit

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose is coherent and the CLI install source appears legitimate, but the actual data path routes PublisherKit authentication and API traffic through Membrane as an intermediary rather than directly to PublisherKit. That third-party credential and request mediation is a meaningful trust expansion, though not strong evidence of malware.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 15, 2026, 10:57 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpublisherkit%2F@9ca4d29d3eaee3639ff11d16118f57a0405ed7d1