cherwell-itsm

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's actions match Cherwell ITSM usage, and the CLI install source is legitimate npm, but the integration is not a direct Cherwell client: it requires a separate Membrane account and routes authentication and API traffic through Membrane's service. That third-party credential and data mediation is the main risk and makes the footprint less aligned with a straightforward Cherwell skill.

Confidence: 86%Severity: 63%
Audit Metadata
Analyzed At
Apr 23, 2026, 10:21 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcherwell-itsm%2F@ad32db047243dd487616d34e22b8b934b3062cfe