transform

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's basic purpose matches a TransForm integration, and the Membrane CLI install source appears consistent with the publisher, but the actual data flow is through Membrane as an intermediary rather than directly to TransForm's official API. That third-party routing, combined with open-ended action creation and a mutable `@latest` CLI install, makes the skill medium risk even without clear malware indicators.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 05:41 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftransform%2F@0390b52943e37734bcda205ac73730c99ea264d2