scrivito
Warn
Audited by Socket on Apr 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s purpose matches its broad CMS integration behavior, and the CLI source appears official, but the core design routes Scrivito access, credentials, and data through Membrane rather than official Scrivito APIs. That third-party mediation is openly documented, so this is not confirmed malware, but it creates medium risk around credential forwarding, data visibility, and trust in an intermediary platform.
Confidence: 84%Severity: 58%
Audit Metadata