checkoutcom

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is mostly coherent with its stated Checkout.com integration purpose and uses an official npm-distributed Membrane CLI from the same vendor ecosystem, so it is not strongly indicative of malware. The main risks are the intermediary data flow through Membrane, broad proxy/API capability, unpinned global CLI install, and real-world payment actions that could be executed via the agent. Overall this is better classified as suspicious/medium-risk rather than malicious.

Confidence: 86%Severity: 57%
Audit Metadata
Analyzed At
Apr 22, 2026, 07:15 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcheckoutcom%2F@07feca8c80138985c1bb1eb6d52d587d73f86f8f