vryno

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities broadly match its purpose, and the CLI install path uses an official npm package rather than a suspicious download-execute chain. However, it routes Vryno operations and authentication through Membrane as an intermediary, and uses unpinned mutable CLI installs (`-g` and `@latest`). This is not clearly malicious, but the third-party credential/data mediation and broad proxy capability make it medium risk rather than benign.

Confidence: 85%Severity: 52%
Audit Metadata
Analyzed At
Apr 2, 2026, 09:50 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fvryno%2F@6ba996bd1f907f04da4bebcf6879e21f6b52a24b