userlist

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is coherent with its stated Userlist-integration purpose and does not show clear malware behavior. Main risk is architectural: it routes authentication and API traffic through Membrane as an intermediary, increasing trust and data exposure beyond a direct Userlist integration. Overall this is better classified as suspicious-to-medium-risk infrastructure dependence, not malicious intent.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 2, 2026, 12:46 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fuserlist%2F@16a9321eee59726eb1c01ea6f8434913f0f9905c