weweb
Warn
Audited by Socket on Apr 3, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated WeWeb integration purpose is partly coherent, but the skill’s real footprint centers on Membrane as a third-party intermediary for authentication, action execution, and raw API proxying. Install trust is moderate because the CLI comes from npm and appears publisher-aligned, but credential routing and data flow are not proportionate to a simple WeWeb skill since all access is funneled through Membrane rather than directly to WeWeb.
Confidence: 88%Severity: 76%
Audit Metadata