verdict-as-a-service
Warn
Audited by Socket on Apr 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's stated purpose broadly matches its capabilities, and the CLI install path is a normal npm-based distribution. However, the core data flow is not direct to Beyond Identity: authentication, credential refresh, and even raw API requests are routed through Membrane as an intermediary, which is a notable trust and data-flow expansion beyond a simple first-party API skill.
Confidence: 88%Severity: 72%
Audit Metadata