bexio

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities mostly align, and the CLI comes from a plausible official npm source. The main risk is architectural: it routes Bexio authentication and API traffic through Membrane as an intermediary, so business data and auth handling depend on a third-party service rather than direct official Bexio API calls. That is disclosed, not hidden, so this is not confirmed malware, but it carries meaningful trust and data-flow risk.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Apr 27, 2026, 06:45 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbexio%2F@0d82b57a82808c9c9d1b7560be2a51695c8c495d