sugarsync

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose matches file-management tasks, and the CLI install source appears consistent with the publisher, but the core design routes SugarSync authentication and API traffic through Membrane as an intermediary rather than directly to SugarSync. That third-party proxy model is broader than necessary for a simple service integration and creates medium security/privacy risk, though there is no clear evidence of outright malware or credential theft.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
Apr 23, 2026, 01:41 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsugarsync%2F@353ce9d16b83be052c5e32800dca6b1a46f876b5