wallarm

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's general purpose matches Wallarm management, and the CLI install source is reasonably legitimate, but the core data flow is through Membrane rather than Wallarm's official API endpoints. That intermediary design creates notable credential-forwarding and data-routing risk disproportionate to a simple Wallarm integration, though there is not enough evidence to call it malicious.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
Apr 21, 2026, 07:12 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fwallarm%2F@95962289f9064408476ae1cd51b85caf60a69721