smugmug
Warn
Audited by Socket on Apr 22, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill is mostly aligned with its stated SmugMug-management purpose, and the CLI install path is relatively trustworthy. The main concern is architectural: authentication and API traffic are routed through Membrane as an intermediary rather than directly to SmugMug, so users must trust a third party with account access and data flows. This makes the skill suspicious-to-medium risk rather than overtly malicious.
Confidence: 87%Severity: 58%
Audit Metadata