reflect

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities broadly match its stated purpose, and the install path uses a legitimate npm package rather than a raw downloader. However, the integration routes Reflect authentication and data through Membrane instead of directly to Reflect, and it asks the agent to execute a third-party CLI with floating latest versions. This looks like a coherent managed-integration skill, but with medium supply-chain and credential-forwarding risk due to intermediary trust and mutable CLI execution.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 23, 2026, 07:14 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Freflect%2F@162aa92324d6a2734b7b996b2dc7237be82304ae