revel-systems

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's capabilities broadly match its stated purpose, and the install path uses an official npm package rather than a raw installer. The main risk is architectural: it routes authentication and API traffic through Membrane's CLI/service instead of direct Revel endpoints, so users must trust a third-party integration layer with credentials and business data. This is not clearly malicious, but it carries medium security risk due to credential forwarding and proxy-based data flow.

Confidence: 83%Severity: 56%
Audit Metadata
Analyzed At
Mar 13, 2026, 02:17 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Frevel-systems%2F@9ae3dabb12630e77d0ded464bb944776bece0bff