strongdm

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose is broadly consistent with StrongDM management, and its install source is an official same-vendor npm package, so this is not confirmed malware. However, it inserts Membrane as a required intermediary for authentication and API proxying, meaning StrongDM data and access flow through a third-party service rather than directly to StrongDM, which is a notable trust and data-flow expansion.

Confidence: 85%Severity: 64%
Audit Metadata
Analyzed At
Apr 22, 2026, 06:43 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fstrongdm%2F@1230aeda3c2bd8031d5b65443ca95d8ace327d9e