act-365
Warn
Audited by Socket on Apr 22, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s purpose and capabilities mostly align with CRM integration, and the install source is an official npm package documented by the same platform. The main risk is that all Act! 365 authentication and API traffic are funneled through Membrane as a third-party intermediary rather than directly to official Act! endpoints, creating a meaningful credential and data-routing trust dependency beyond what the skill title alone suggests.
Confidence: 86%Severity: 52%
Audit Metadata