sugarsync
Warn
Audited by Socket on Apr 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's purpose matches file-management tasks, and the CLI install source appears consistent with the publisher, but the core design routes SugarSync authentication and API traffic through Membrane as an intermediary rather than directly to SugarSync. That third-party proxy model is broader than necessary for a simple service integration and creates medium security/privacy risk, though there is no clear evidence of outright malware or credential theft.
Confidence: 87%Severity: 61%
Audit Metadata