skillzrun

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The SkillzRun integration is broadly coherent with its stated purpose: it uses Membrane as the authorized conduit to discover and execute SkillzRun actions, with credentials managed by Membrane and interactions routed through Membrane proxy. The footprint is proportionate and aligns with a developer-oriented integration pattern. Some minor risk signals include reliance on a CLI with potentially broad permissions and the absence of explicit per-action permission scoping in the documentation, but there are no evident credential Harvesting, unverifiable binaries, or autonomous destructive capabilities. Overall, the risk posture is Low-to-Medium and acceptable for a legitimate developer tool under the described workflow.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 04:48 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fskillzrun%2F@5b6864c7730372a3b9ae446afa159d067dcd9452