companyhub

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly coherent for a CompanyHub integration, and the CLI comes from an official npm package, so this is not strong evidence of malware. However, all authentication and CRM data are intentionally routed through Membrane instead of directly to CompanyHub, creating a meaningful third-party trust and data-handling risk that is higher than a direct official API integration.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 24, 2026, 11:50 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcompanyhub%2F@f6e5fb1436da57c0a37f8de26e5fa41b26251acd