applicantstack

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is a documentation/README describing use of the Membrane CLI to integrate with ApplicantStack. Functionally it is consistent with its stated purpose: installing a CLI, creating a connection, running actions, and proxying requests. The primary security concerns are supply-chain and third-party trust: global npm install of a CLI (standard but a supply-chain vector), and routing credentials and proxied API requests through the Membrane service centralizes sensitive data and creates a credential-forwarding/data-exfiltration risk if Membrane or accounts are compromised. There is no explicit malicious or obfuscated code in the provided text. The risk is primarily operational and trust-based rather than demonstrably malicious code in this skill file. Users and organizations should evaluate Membrane's security practices, minimize global installs where possible, and treat the Membrane tenant and connection IDs as sensitive.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 08:57 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fapplicantstack%2F@0150b8f0b39aec14ffe2221646ae1912f89a72d6