snatchbot

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and commands are mostly coherent, and installation uses an official npm package rather than an unknown binary. However, all SnatchBot access and credential handling are routed through Membrane as an intermediary, not directly to SnatchBot, which creates medium trust and data-flow risk. This looks like a legitimate integration pattern with elevated third-party mediation risk, not confirmed malware.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 21, 2026, 07:12 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsnatchbot%2F@655a88a6c2b1fb6b5ef2a025eae4d3933480a5dc