booqable

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is broadly aligned with its stated Booqable integration purpose and uses an official npm-distributed CLI from the same vendor ecosystem, so it does not look malicious. Risk comes from the architecture: Booqable access and credentials are mediated through Membrane, and the proxy/action model can perform broad read/write operations on business records. Overall this is coherent but trust-heavy, so suspicious-by-caution rather than benign.

Confidence: 86%Severity: 54%
Audit Metadata
Analyzed At
Apr 23, 2026, 06:53 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbooqable%2F@1c9a7a2c77394fd20a6d98a88351cd08c584fb60