amocrm

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This SKILL.md documents a legitimate Membrane-based integration with AmoCRM and is internally consistent: capabilities (discover/run actions, proxy requests) match the stated purpose. The primary security consideration is centralization of credentials and traffic at the Membrane service — users must trust Membrane with OAuth tokens and proxied request/response data. The npm installation step is standard but, as with any global npm package, requires trusting the package owner. I found no indications of hidden malicious behavior, obfuscated payloads, or credential-harvesting instructions in the provided text.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 08:57 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Famocrm%2F@411325df1bf78d235da00bbc6e1f5c38ecfd5ac8