t2m-url-shortener

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities broadly match its stated T2M integration purpose, and the CLI comes from an official npm package tied to the same vendor. However, all authentication and API activity are routed through Membrane as a third-party intermediary rather than directly to T2M, and the skill asks the agent to install and trust that external CLI with mutable latest-tag execution. This is not confirmed malicious, but it introduces medium risk through credential forwarding and proxy-style data flow.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
Apr 30, 2026, 12:03 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ft2m-url-shortener%2F@b4f9c1fa6a076e97e0622d860414535f664ceb5b