tick

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core purpose fits Tick integration, and the install path is an official npm package from the same vendor ecosystem. However, all Tick access and authentication are mediated through Membrane rather than direct official Tick APIs, and the skill can create/run remote actions dynamically. This is not clearly malicious, but it meaningfully expands trust and routes credentials/data through a third-party integration platform.

Confidence: 84%Severity: 53%
Audit Metadata
Analyzed At
Apr 22, 2026, 08:22 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftick%2F@b63e20255e58300a47d7c792b0d36d51e37c53c5