rudderstack-http

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is not overtly malicious and uses an official-looking npm-distributed CLI, but its actual operation depends on Membrane as a third-party intermediary for authentication and API proxying rather than direct RudderStack access. That data-flow indirection, combined with broad generic capabilities and unpinned CLI execution, makes the skill higher-risk than a simple vendor-direct API integration.

Confidence: 82%Severity: 56%
Audit Metadata
Analyzed At
Mar 20, 2026, 11:26 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Frudderstack-http%2F@ee93cb6b414dd286132b72654574b6ba4d8e5c56