civicrm

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities fit its CiviCRM purpose, and the CLI comes from an official npm package tied to the same vendor, so there is no strong malware signal. However, all CRM access and credentials are routed through Membrane rather than directly to CiviCRM, and the proxy/request features plus record mutation abilities create meaningful third-party trust and data-flow risk.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 21, 2026, 04:39 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcivicrm%2F@1fa8444f225a551e320cfdda25f5aa2e3f14037d