channeladvisor

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's core purpose is coherent, and the CLI install path appears legitimate via npm, so this is not confirmed malware. But ChannelAdvisor access and data are funneled through Membrane as a third-party broker, and the skill enables consequential commerce actions with only lightweight safeguards, making the overall risk medium.

Confidence: 82%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 02:55 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fchanneladvisor%2F@8cdca291aecc443ab5d682fda0c485b1496adeee