textanywhere

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Suspicious. The skill's purpose and capabilities mostly align, and the CLI install path is an official npm distribution, so this is not overt malware. However, the integration routes TextAnywhere access through Membrane as an intermediary rather than directly to official TextAnywhere APIs, creating a notable third-party trust and data-flow risk; this makes the skill higher-risk than a direct vendor integration but not fundamentally malicious.

Confidence: 88%Severity: 57%
Audit Metadata
Analyzed At
Apr 2, 2026, 05:26 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftextanywhere%2F@90076110e7e8a5838e8f7c9b1454cb0f64d8573f