commercetools

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is coherent with its stated purpose and uses an official npm-distributed CLI from the same publisher, so it does not look malicious. The main concern is data-flow integrity: Commercetools access is mediated through Membrane, which becomes a third-party gateway for authentication and API traffic. Overall this is a medium-risk, suspicious-by-design integration pattern rather than confirmed malware.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 23, 2026, 08:24 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcommercetools%2F@1be522d4e05fe080ff99b411b0f2040c882f2d8a