typesense

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s stated purpose matches its capabilities, and installation uses an official npm package, so this is not overt malware. However, the integration materially shifts trust from direct Typesense API access to Membrane as a credential-storing proxy and action gateway, which creates medium security risk and weaker data-flow integrity than a direct official API pattern.

Confidence: 89%Severity: 56%
Audit Metadata
Analyzed At
Apr 2, 2026, 04:11 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftypesense%2F@928273279af6d897c7c292b91f153c5ff4753eae