employment-hero

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's overall purpose and capabilities are coherent, and the installer source is legitimate. The main risk is architectural: it requires a third-party Membrane CLI/service to mediate Employment Hero authentication and data access, including sensitive HR/payroll operations, and uses a mutable CLI version plus dynamic action creation. This is not confirmed malware, but it is a medium-risk integration because credentials and data are delegated through an intermediary rather than flowing directly to Employment Hero.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 02:55 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Femployment-hero%2F@fd52099ddf395f4b01c253805ec6613eaff3d8e5