smarty

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The Membrane CLI install path appears official and proportionate on its own, but the skill is internally inconsistent about what 'Smarty' means and what it can do. Its real data flow also routes requests through Membrane's proxy rather than directly to the target service, which is a meaningful trust-boundary expansion. Overall this looks more like a mislabeled or confused skill than confirmed malware, but the purpose-capability mismatch warrants caution.

Confidence: 89%Severity: 61%
Audit Metadata
Analyzed At
Apr 21, 2026, 09:05 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsmarty%2F@62a2339fdf14f057ebb728036ad56a29b0445dab