webflow

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is functionally coherent for Webflow management, and its install path is relatively standard via npm. The main risk is data-flow integrity: Webflow authentication and API traffic are routed through Membrane's CLI and proxy service rather than directly to Webflow, creating a meaningful third-party trust and visibility layer. Overall this is better classified as suspicious/medium-risk than malicious.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Mar 15, 2026, 09:54 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fwebflow%2F@26d93c53c7aec912ac0cc018e0e26e22c0f31a93