supernotes

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s functionality is mostly aligned with its purpose, and the CLI install path is from an official npm package tied to the publisher. However, all Supernotes access and token handling are mediated through Membrane rather than direct official Supernotes APIs, adding a third-party trust boundary and credential/data routing layer that is not strictly necessary for this task. This looks more like a managed integration platform than outright malware, but the intermediary architecture raises medium security risk.

Confidence: 85%Severity: 54%
Audit Metadata
Analyzed At
Apr 21, 2026, 11:21 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsupernotes%2F@88311bc4a1a5692e5d92a9237aa6c1f7948acb1b