bancontact-payconiq-company

Warn

Audited by Socket on Apr 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and capabilities are mostly aligned, and the CLI install path is official npm-based rather than an unverifiable binary. The main concern is data-flow integrity: instead of calling Bancontact Payconiq Company directly, the skill sends requests and managed credentials through Membrane as an intermediary, which is documented but broadens trust and centralizes sensitive payment-integration traffic in a third-party gateway.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 25, 2026, 11:04 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbancontact-payconiq-company%2F@d21d883a7ec072e6067f220ae1ebba68ba6da2f2