thinq

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly coherent as a Membrane-powered ThinQ connector and uses an official npm-distributed CLI from the same publisher, so there is no strong malware evidence. However, the skill routes ThinQ access through Membrane as a third-party proxy, stores/refreshes credentials server-side, and contains notable documentation mismatches about ThinQ’s purpose, which makes the data flow less trustworthy than a direct official API integration.

Confidence: 86%Severity: 52%
Audit Metadata
Analyzed At
Apr 21, 2026, 07:45 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fthinq%2F@5b1793008e343f59dd729c184c66b844ac211808