self-integration

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The skill is internally consistent with Membrane's published purpose, and there is no local download/execute behavior or unverifiable binary. However, it grants a third-party platform broad delegated control over many external apps, forwards sensitive data and action inputs through that intermediary, and enables high-impact real-world actions across a very wide scope. The main risk is not malware but overbroad authority and third-party mediation of credentials and app activity.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Mar 18, 2026, 11:07 PM
Package URL
pkg:socket/skills-sh/membranehq%2Fagent-skills%2Fself-integration%2F@abbd209d6845eca003a9eb5245b78ef25e132da6