tiledesk

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s stated purpose matches its general capabilities, and the CLI comes from an official registry, so this is not overtly malicious. However, it routes authentication, credentials, and Tiledesk operations through Membrane as a third-party intermediary, and dynamic action creation expands remote behavior beyond a fixed connector. Main risk is delegated trust and intermediary data flow, not confirmed malware.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Apr 22, 2026, 05:40 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftiledesk%2F@46cc534f8e72441e80cd0fb9c1a69a15f24a1176