clockify

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's capabilities broadly match Clockify integration, and the CLI install source is a normal npm package, but the core design routes authentication and all API activity through Membrane instead of Clockify's official API. That third-party gateway is proportionate to the stated Membrane-based product model, yet it creates medium data-flow risk because Clockify access and results are mediated by an external service.

Confidence: 84%Severity: 54%
Audit Metadata
Analyzed At
Apr 22, 2026, 06:43 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fclockify%2F@def79582658d795eebfc07d57b677351524e9177