box

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Box skill presents a coherent and proportionate integration: it uses a well-known CLI tool (Membrane) to orchestrate Box operations via authenticated, server-managed credentials, with Box API access routed through Membrane’s proxy. There are no obvious credential harvesting, unintended data exfiltration, or arbitrary download/execution patterns. Risks are low to moderate and primarily revolve around proper configuration of Membrane authentication and access scopes. Overall, the footprint aligns with the stated purpose and remains within acceptable security boundaries for a developer-oriented integration skill.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 09:00 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fbox%2F@e2891844689776bad418a8c8092fe887adf20b55