watsonx-ai

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly coherent for a Watsonx integration and uses a same-org CLI from npm, so it does not look malicious. However, it depends on Membrane as an intermediary for authentication and API proxying instead of calling IBM directly, which creates medium data-flow and trust risk that is broader than a simple direct integration.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 2, 2026, 03:13 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fwatsonx-ai%2F@cd2b53c17b1ccb59bc15eacce394d0bce68842a3