surveybot
Warn
Audited by Socket on Apr 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's overall purpose is coherent, and the CLI install path is standard, but the integration is built around Membrane as a third-party credential and request intermediary rather than direct official API access. That proxying and server-side credential handling materially increase trust and data-flow risk, though there is no clear evidence of malware or overt credential theft behavior.
Confidence: 88%Severity: 57%
Audit Metadata