wb

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The install source is relatively trustworthy and same-org, so this is not a clear malware or fake-installer case. However, the skill’s real footprint is a Membrane integration that mediates W&B auth and traffic through a third-party proxy/CLI, which is broader and riskier than a direct W&B skill.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 2, 2026, 06:04 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fwb%2F@bbd8a74e711322b03a70821e37262e831b3ed8e9