alexishr

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

This file is documentation that instructs users to use Membrane as a proxy and credential manager for interacting with AlexisHR. The main security concerns are trust centralization (all credentials and request payloads routed through Membrane), supply-chain risks from installing an npm CLI globally and using unpinned versions, and lack of transparency on data retention or logging by Membrane. I found no direct indicators of malware or backdoors in the documentation text itself. Recommended mitigations: pin CLI versions, verify package provenance, run installs in controlled environments, review Membrane's privacy/security docs, and avoid sending highly sensitive data through third-party proxies unless acceptable under your threat model.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 4, 2026, 08:57 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Falexishr%2F@ae1bb597c2fe73c8970ddc167a078b3f107220e4