yugabyte

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is coherent as a Membrane-based Yugabyte integration guide, and its CLI install path is relatively trustworthy. However, its real footprint is not direct Yugabyte access: it requires a Membrane account, sends auth and request traffic through Membrane, and encourages proxying all external app communication via that intermediary. That third-party credential/data routing is broader than a plain Yugabyte skill and raises medium security risk despite not showing clear malware behavior.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 2, 2026, 01:42 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fyugabyte%2F@76b4cd1688b3c671e8c55b6ff9f86b3ac77f2952