r3
Warn
Audited by Socket on Apr 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The Membrane CLI install path appears legitimate and same-publisher, but the skill's stated purpose is inconsistent with its listed data model, and all auth/API access is funneled through Membrane's intermediary service rather than clearly documented official R3 endpoints. The main risk is documentation/target mismatch plus third-party mediation of connected-app access, not confirmed malware.
Confidence: 84%Severity: 58%
Audit Metadata