starton

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is internally coherent as a Membrane-hosted connector guide, and the CLI source looks proportionate and official, but the actual integration works by routing Starton authentication and API traffic through Membrane rather than directly to Starton. That intermediary credential/data path and mutable `npx @latest` usage raise meaningful security risk even without clear malicious intent.

Confidence: 88%Severity: 62%
Audit Metadata
Analyzed At
Apr 3, 2026, 02:43 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fstarton%2F@9eb0d79106c180b4a2e7ee83ba4009c78ef91bc5