veritone

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s general function matches its stated Veritone integration purpose, and the CLI comes from npm rather than an opaque installer. However, it relies on Membrane as a third-party intermediary for authentication, credential lifecycle, and API execution instead of using Veritone directly, creating a notable data-flow and trust expansion that is only partly disclosed by the purpose statement.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Apr 21, 2026, 11:20 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fveritone%2F@0caf19ca2b7b83316b9132fa129e325716573ada