pushover

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose broadly matches its capabilities, and the CLI install appears to come from the publisher's documented npm package. However, the integration routes Pushover access through Membrane's CLI and proxy service, creating third-party credential/data handling and enabling external actions like sending notifications; this makes it medium risk rather than benign.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Mar 21, 2026, 09:57 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpushover%2F@1f23019e84c794fde55b3db4e6c3a88f8f3bd155