saucelabs

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly coherent with its stated purpose, and the CLI comes from an official npm package tied to the same publisher, so this is not confirmed malware. However, the core design routes Sauce Labs authentication and operations through Membrane as an intermediary rather than official Sauce Labs APIs, and it uses mutable `@latest` installs/execution. That makes the skill medium risk: consistent in purpose, but with notable third-party trust and data-flow concerns.

Confidence: 86%Severity: 57%
Audit Metadata
Analyzed At
Apr 22, 2026, 06:43 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsaucelabs%2F@381de06d6090683e53b3fcac136e3735f9ef1b7d