terraform

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose and commands are mostly coherent, and the Membrane CLI appears to be an official npm-distributed tool. However, the integration is not a direct Terraform skill: API calls and auth are funneled through Membrane's proxy/service, creating a meaningful third-party data-flow and credential-handling risk disproportionate to a pure Terraform connector.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 08:26 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fterraform%2F@4878f1857bb69d3dbf835b341ccc5e6fb8d4e663