softr

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is internally coherent as a Membrane-based Softr integration, and its install source is a real same-brand npm package rather than an obviously malicious payload. However, it materially expands trust by routing authentication and application data through Membrane instead of Softr’s official API directly, and it uses an unpinned external CLI plus remotely generated actions. That makes it higher-risk than a direct official Softr integration, but not clearly malicious.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 04:14 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsoftr%2F@002010e0886eb04921f3452956efe1727b0e1b2b