strapi

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is coherent with its stated purpose and uses an official vendor CLI from npm, so it does not look malicious. However, it requires a Membrane account and routes Strapi operations through Membrane’s proxy and credential infrastructure rather than directly to Strapi, creating a third-party data and trust dependency that raises medium security risk.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 22, 2026, 07:42 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fstrapi%2F@368c59f8d3597466d93f3fbefe7adb8e15ed4ebd