samsara

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent as a Samsara integration, and the CLI comes from the same vendor via npm, so this is not overt malware. However, it routes Samsara authentication and API traffic through Membrane as an intermediary rather than directly to official Samsara endpoints, creating meaningful trust and data-flow risk beyond a simple direct API skill.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
Apr 21, 2026, 06:09 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsamsara%2F@58a7243e5fe657dc1519bd757ddf61917ef2788a