readme-com

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's high-level purpose matches Readme.com management, and the CLI install path is reasonably legitimate via npm, but the actual data flow is routed through Membrane rather than directly to Readme.com. Requiring a separate Membrane account and proxying authenticated API requests through a third-party intermediary is a meaningful trust and credential-handling concern, making this riskier than a normal first-party API integration.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Mar 16, 2026, 06:30 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Freadme-com%2F@52e0acfd13ff8826c5391f7e4a56df27548e976b