shortcut

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core capability fits project-management automation, and the CLI install path is reasonably legitimate, but the skill is not a direct Shortcut integration. It requires trust in Membrane as an intermediary for authentication, data access, and action execution, which expands credential and data exposure beyond what the title suggests. Main risk is third-party credential/data routing, not confirmed malware.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Apr 22, 2026, 12:53 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fshortcut%2F@c5fe1607dd619ee7dc42c42c81f28670da075329