visitor-queue

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s main function is coherent, and the CLI install path is from an official npm package, so this is not overt malware. However, it routes Visitor Queue access, credentials, and arbitrary proxy requests through Membrane rather than directly to official service endpoints, creating a third-party trust and data-flow concern that is broader than a simple first-party integration.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 21, 2026, 04:12 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fvisitor-queue%2F@63fcc34a91ea302634fec0261ebf8628c05309ff