bamboohr

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The BambooHR skill presents a coherent and proportionate integration workload: it leverages the Membrane CLI for authentication and BambooHR API access via authorized proxies, with actions that map to common HR data operations. The install path uses official npm registries, and credential handling is delegated to Membrane, which mitigates local secret exposure. While there are normal security considerations around centralized credential handling and data in transit/logs, the overall footprint is aligned with the stated purpose. Remain vigilant for potential supply-chain or data-flow exposures in real deployments, particularly around logging, token storage, and proxy configurations.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 01:55 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbamboohr%2F@f05e6dc54f1a7472992a24cae233cfe1023f5d6c