snapshot

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly coherent as a Membrane-based SnapShot connector and uses an official npm package, so it does not show clear malware traits. However, all service access and credential handling are routed through Membrane's intermediary CLI/proxy rather than directly to SnapShot, which creates a meaningful data-flow and trust expansion that is only partially reflected in the skill's stated purpose.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 21, 2026, 04:12 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsnapshot%2F@6ca34d643cd9e5fdb129cec74b8fd5f552fd16a2