semaphore

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Semaphore integration skill is coherent with its stated purpose: it leverages Membrane's CLI to manage Semaphore data with authentication handled server-side, and uses Membrane's proxy to interface with Semaphore API. The install path uses official npm tooling, and credentials are not stored locally but managed by Membrane, which aligns with a secure, developer-focused integration. Overall, the risk is low to moderate (securityRisk around 0.3–0.4, malware near 0.0–0.1) given proper Membrane security, with no evident credential harvesting or arbitrary file/system access. The main considerations are ensuring Membrane's proxy remains secure and that any emitted logs do not inadvertently leak session tokens.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 06:33 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsemaphore%2F@029b6093358a2fbe10fd5f674a54ba11f84a5dc5