trint

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and capabilities are broadly aligned, and the install path uses an official npm package tied to the same product. The main concern is data-flow integrity: all Trint access and credential handling are routed through Membrane as an intermediary, so the user must trust a third-party platform with authentication and API mediation rather than using Trint directly. This is not clearly malicious, but it is a meaningful trust expansion and medium security risk.

Confidence: 87%Severity: 52%
Audit Metadata
Analyzed At
Apr 21, 2026, 02:53 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftrint%2F@06336ea80b3de146c7cdedac17ae3d7db155c4ef