witai

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is internally coherent as a Membrane-based Wit.ai integration and uses an official npm-distributed CLI, so it does not look overtly malicious. However, its actual data flow routes Wit.ai operations and auth handling through Membrane as an intermediary rather than directly to official Wit.ai APIs, which creates meaningful third-party trust and data exposure risk beyond a simple API guide.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 2, 2026, 04:12 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fwitai%2F@b1901acb25e4551ffc1d8d963ac92549674d8a92