whosonlocation

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities broadly match its stated purpose, and the CLI install path is from an official npm package tied to the stated publisher. The main concern is data-flow integrity: authentication and API requests are funneled through Membrane as a third-party intermediary rather than directly to WhosOnLocation, which increases credential and data exposure beyond a direct integration. This is not clearly malicious, but it is medium risk and should only be used if the user accepts Membrane as the trusted broker.

Confidence: 87%Severity: 54%
Audit Metadata
Analyzed At
Apr 2, 2026, 03:36 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fwhosonlocation%2F@a9d35a6d43b38c4f776dec8a6ce6051bdd2c49ab