volterra

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is mostly coherent with its stated Volterra-integration purpose and uses an official npm-distributed CLI, so it is not clearly malicious. The main concern is architectural: Volterra access is mediated through Membrane, which manages credentials server-side and proxies API traffic, creating a third-party trust and data-flow dependency. Overall classification: SUSPICIOUS due to intermediary credential/data routing and broad proxy scope, but not indicative of confirmed malware.

Confidence: 84%Severity: 57%
Audit Metadata
Analyzed At
Apr 21, 2026, 08:13 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fvolterra%2F@ed6cabec7b6b240357584266d30b524f52a0e0a3