upviral
Warn
Audited by Socket on Apr 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is internally coherent for a Membrane-hosted UpViral integration and uses an official npm-distributed CLI, so install trust is relatively normal. However, all authentication and API traffic are mediated by Membrane rather than going directly to UpViral, creating a notable third-party credential and data-routing risk that is higher than a direct official API integration.
Confidence: 89%Severity: 58%
Audit Metadata