aftership

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is a documentation/manifest for integrating AfterShip through the Membrane platform. The content is internally consistent: capabilities, install steps, and data flows align with the stated purpose. The primary security concerns are supply-chain and operational trust: installing the @membranehq/cli from npm and routing all API requests and credentials through the Membrane service centralizes trust and increases exposure if Membrane or its CLI were compromised. The skill text itself contains no direct malicious instructions, no credential-harvesting prompts, and no download-and-execute shell commands. Recommendation: treat this skill as acceptable for use only if you trust the Membrane provider and audit the CLI/package provenance; otherwise avoid installing global CLIs from unverified sources.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 08:56 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Faftership%2F@61e45dbe0ca231f0be6d2e0dac1be8a15e1ac96e