bambora

Warn

Audited by Socket on Apr 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities broadly match its stated Bambora integration purpose, and the Membrane CLI install path is from an official registry tied to the publisher. The main concern is data-flow integrity: Bambora credentials and API traffic are mediated by Membrane rather than sent directly to official Bambora endpoints, creating third-party credential forwarding and proxy access to payment-related data. This is not clearly malicious, but it is a meaningful trust and privacy risk for a payment integration skill.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
Apr 25, 2026, 11:04 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbambora%2F@c8c7001ce1b69f91ffd48371be458528c2aa16bc