actblue

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is a documentation-only integration instructing users to install and use the Membrane CLI to interact with ActBlue. There are no embedded malicious payloads, hardcoded secrets, or obfuscated code. The primary security consideration is that all authentication and proxied API requests flow through Membrane — a third-party platform that will see credentials and request payloads. That design is reasonable for a connector but increases the trust and attack surface: if Membrane or its CLI/package is compromised, ActBlue credentials and potentially sensitive donation data could be exposed. Recommend users audit and trust Membrane as a service/publisher before use, and review Membrane's data handling and retention policies. No direct evidence of malware was found in this document.

Confidence: 85%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 08:57 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Factblue%2F@47707e2eaefa8b32935a23a3363922d7ab571e34