teamgantt

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly match its stated TeamGantt integration purpose, and the CLI install source appears to be the publisher’s official npm package. However, it routes API access and credential lifecycle through Membrane instead of directly to official TeamGantt endpoints, creating a third-party intermediary data flow that increases trust and privacy risk; the unpinned `npx @latest` usage adds minor supply-chain risk.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 3, 2026, 10:21 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fteamgantt%2F@4f025e8aaf8af5eb00fb83ad035163359022087b