amazon-advertising
Warn
Audited by Socket on Mar 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
This skill documentation is coherent with its purpose: it delegates authentication and API proxying to the Membrane service and provides CLI usage instructions. There is no embedded malicious code or obvious backdoor. Primary risks are supply-chain risks from installing a global npm CLI without pinned versions and the trust decision required by routing credentials and API traffic through the Membrane backend. Operators should review Membrane's security and privacy policies and consider pinning CLI versions before installing in sensitive environments.
Confidence: 85%Severity: 75%
Audit Metadata