elastic-path

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities broadly match its stated Elastic Path integration purpose, and the CLI install path is from an official npm package rather than an opaque binary. However, the skill routes all authenticated Elastic Path activity through Membrane's third-party proxy and account system instead of direct official APIs, creating a meaningful trust-boundary and credential-forwarding concern. This looks more like a managed integration gateway than malware, but the intermediary data flow and unpinned @latest execution make it medium risk rather than benign.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 09:51 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Felastic-path%2F@c736e54668793011d0e041bcd0f64d79cf7a31c5