contractbook

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities broadly align, and the CLI comes from an official registry path tied to the stated vendor, so this is not outright malicious. However, it routes Contractbook access and authentication through Membrane as an intermediary service, expanding data exposure beyond the official API path, and uses mutable `@latest` installs. Risk is mainly third-party data/credential mediation plus moderate supply-chain hygiene concerns, not confirmed malware.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 21, 2026, 10:54 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcontractbook%2F@cccbaa1d34c8d75e4e6d1631b3543357a1bf1f4a