callrail

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose and capabilities are mostly coherent, and the CLI comes from an official npm package, so this is not overtly malicious. However, it introduces a third-party intermediary (Membrane) for authentication and API traffic, uses a broad proxy mechanism, and enables real-world actions like sending texts, which raises medium security risk beyond a direct CallRail integration.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:52 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcallrail%2F@9b262663ac67582f687adb838870b99e763e36d3