customerio

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's basic purpose is coherent, and its CLI install path is relatively trustworthy, but the core integration is mediated by Membrane rather than talking directly to Customer.io. That third-party proxy/auth model is a significant data-flow and trust-boundary expansion for a Customer.io skill, raising medium-high security risk without clear evidence of outright malware.

Confidence: 85%Severity: 68%
Audit Metadata
Analyzed At
Apr 21, 2026, 08:12 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcustomerio%2F@8b1da640758a97518561cfb114116c924fa3e8aa