yuki

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and capabilities are broadly aligned, and the install source is an official npm package tied to the same vendor, so this is not overt malware. However, the integration routes Yuki access through Membrane as an intermediary, creating third-party credential/data exposure and a broader trust boundary than a direct Yuki integration; combined with mutable CLI install/exec instructions and broad proxy capabilities, this makes the skill medium risk.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 2, 2026, 01:24 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fyuki%2F@2e9edd913ef241a0e31804a8bcb1b5f4425210a3