usersketch

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is not overtly malicious and uses a legitimate npm-published CLI, but its actual footprint depends on a third-party intermediary (Membrane) for auth and all API access, and the claimed target service is ambiguous because the skill name and linked official docs do not match. The install source is reasonably trustworthy, yet purpose-capability alignment and data-flow integrity are only partially coherent.

Confidence: 85%Severity: 62%
Audit Metadata
Analyzed At
Apr 2, 2026, 01:00 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fusersketch%2F@469395865a30316914395167146efaf4426acb08