timely-time-tracking
Warn
Audited by Socket on Apr 22, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is mostly coherent for a Timely integration and uses an official-looking npm-distributed CLI from the same product family, but it routes authentication and API traffic through Membrane as an intermediary rather than directly to Timely. That disclosed gateway model raises medium security risk and trust-boundary concerns, though there is not enough evidence of outright malicious intent.
Confidence: 86%Severity: 56%
Audit Metadata