wave-financial

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is internally coherent for a Membrane-published Wave integration, and its CLI install path appears official. The main risk is architectural: Wave credentials and API traffic are mediated by Membrane rather than going directly to Wave, and the skill enables high-impact financial actions through a broad proxy interface. This looks more like a high-trust third-party integration than malware, but it carries medium security risk and should be used only when that intermediary model is acceptable.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 2, 2026, 04:40 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fwave-financial%2F@57bd5a775a10ee3248380c29a620b502dc754367