connectall

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's capabilities mostly fit its stated ConnectALL integration purpose, and the installer is an official npm package rather than an obvious malware dropper. The main concern is data-flow integrity: all auth and API traffic are funneled through Membrane as an intermediary, not directly to ConnectALL, so the user must trust a third-party CLI/service with credentials, token refresh, and potentially sensitive ConnectALL data. This is coherent with the product design but raises medium security risk.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 01:42 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fconnectall%2F@63409340a0e62a01181ecb628c07c286a2c9681d