integrate-any-external-app

Fail

Audited by Socket on Feb 24, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill description and workflow are internally coherent with the stated purpose of integrating external apps through the Membrane CLI and API. It does not embed malicious code or direct downloads; it relies on official tooling and centralized data flows through Membrane. Key security considerations revolve around local credential storage (~/.membrane/credentials.json) and trusting Membrane as the data processor for all action inputs/outputs. No obvious malicious behavior detected; risk is moderate due to centralized data handling and local credential storage, but within an intended enterprise integration model.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 24, 2026, 11:27 PM
Package URL
pkg:socket/skills-sh/membranehq%2Fagent-skills%2Fintegrate-any-external-app%2F@aec8bf09c4cf2816916ce33e20f766ae300a51b8