bancontact-payconiq-company
Warn
Audited by Socket on Apr 25, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's purpose and capabilities are mostly aligned, and the CLI install path is official npm-based rather than an unverifiable binary. The main concern is data-flow integrity: instead of calling Bancontact Payconiq Company directly, the skill sends requests and managed credentials through Membrane as an intermediary, which is documented but broadens trust and centralizes sensitive payment-integration traffic in a third-party gateway.
Confidence: 87%Severity: 56%
Audit Metadata