amocrm
Warn
Audited by Socket on Mar 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
This SKILL.md documents a legitimate Membrane-based integration with AmoCRM and is internally consistent: capabilities (discover/run actions, proxy requests) match the stated purpose. The primary security consideration is centralization of credentials and traffic at the Membrane service — users must trust Membrane with OAuth tokens and proxied request/response data. The npm installation step is standard but, as with any global npm package, requires trusting the package owner. I found no indications of hidden malicious behavior, obfuscated payloads, or credential-harvesting instructions in the provided text.
Confidence: 80%Severity: 75%
Audit Metadata