riskadvisor

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core capability fits the stated purpose, and the CLI install path is plausibly official, but the skill routes RiskAdvisor access through Membrane as an intermediary rather than directly to the official service. That third-party proxy model and mutable CLI install make this higher-risk than a direct official API integration, though not clearly malicious.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 03:37 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Friskadvisor%2F@6bac145a7978403b89aa66d12b253684530b8e90