weweb

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated WeWeb integration purpose is partly coherent, but the skill’s real footprint centers on Membrane as a third-party intermediary for authentication, action execution, and raw API proxying. Install trust is moderate because the CLI comes from npm and appears publisher-aligned, but credential routing and data flow are not proportionate to a simple WeWeb skill since all access is funneled through Membrane rather than directly to WeWeb.

Confidence: 88%Severity: 76%
Audit Metadata
Analyzed At
Apr 3, 2026, 07:22 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fweweb%2F@4ffd1a701977146c8c4db9fc808005c341c1358f