chmeetings

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s core purpose is coherent, and the CLI install path appears to use an official npm package rather than an unverifiable binary. However, the integration is mediated entirely through Membrane, which acts as a third-party credential and data proxy instead of using ChMeetings’ official API directly. That intermediary routing is proportionate to the stated Membrane-based design but raises moderate security risk due to credential delegation and broad access to church-management data and write actions.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 24, 2026, 03:48 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fchmeetings%2F@414f52f99fd19605f2a1f450cd539dca4d063227