typeform

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities match its stated Typeform integration purpose, and the CLI install path is a normal npm-based distribution rather than a covert payload. However, the skill requires a Membrane account and routes Typeform authentication and API traffic through Membrane instead of direct official Typeform API usage, creating a third-party credential/data mediation risk and enabling impactful external actions.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Mar 14, 2026, 12:16 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftypeform%2F@1254bbd140d8cdf0162d506c27ed36012a9f5dab