schedule-it

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is not overtly malicious and its capabilities generally match a Schedule it integration, but it introduces a third-party intermediary (Membrane) for authentication and data access instead of using Schedule it’s official API directly. The npm-based CLI install is relatively standard, yet the main risk is credential and data routing through Membrane infrastructure, plus dynamic action creation on that platform. This is a coherent integration skill, but trust is meaningfully expanded beyond Schedule it itself.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 08:22 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fschedule-it%2F@e955374def4094f139a0312d3dbbd5dd2b0e03de