skyciv

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is largely coherent for a SkyCiv integration and uses an official npm-published CLI from the same vendor, so it is not strongly indicative of malware. However, all authentication and API access are mediated through Membrane rather than direct SkyCiv endpoints, creating meaningful third-party credential and data-routing risk; combined with floating CLI versions, this makes the skill medium-risk rather than benign.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 02:53 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fskyciv%2F@1576baf395cc24fd9a46b511096292145672f528