waydev

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

This skill is mostly coherent with its stated purpose and uses an official npm-distributed Membrane CLI, so it does not look malicious. The main concern is architectural: a Waydev integration is implemented through Membrane as a third-party intermediary that manages authentication and proxies requests, so Waydev data and delegated access flow through Membrane rather than directly to official Waydev APIs. Overall this is better classified as suspicious-than-benign on data-flow integrity grounds, but not malicious.

Confidence: 85%Severity: 52%
Audit Metadata
Analyzed At
Apr 2, 2026, 03:40 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fwaydev%2F@8da6ff65377be25455976dbbf6385af83a852c06