slybroadcast

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly coherent with its stated purpose, and the CLI appears to be an official same-vendor npm package, so this is not confirmed malware. However, all access is mediated through Membrane rather than direct Slybroadcast APIs, credentials and activity are entrusted to that intermediary, the install is unpinned (`@latest`), and the skill can generate and execute new actions with real-world messaging consequences. This is a medium-risk third-party integration pattern, not a clearly malicious skill.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 22, 2026, 03:38 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fslybroadcast%2F@b5c977925d1c7605eabd779c0e929a8046555264