reclaim
Warn
Audited by Socket on Apr 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's purpose broadly matches its capabilities, and the CLI install path is a normal official npm dependency. The main concern is data-flow integrity: Reclaim API access is funneled through Membrane's intermediary platform and proxy, so account access and data are not confined to the official Reclaim API path. This is not clearly malicious, but it is a meaningful trust expansion beyond a direct Reclaim integration.
Confidence: 84%Severity: 52%
Audit Metadata