enfuce

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly coherent for an Enfuce integration, and the CLI install path appears legitimate via the official npm package. The main concern is architectural: it routes Enfuce authentication and data through Membrane as an intermediary for a sensitive financial platform, with mutable CLI installs and action-generation capabilities increasing security exposure. This is not confirmed malware, but it is higher-risk than a direct first-party Enfuce client.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 23, 2026, 06:40 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fenfuce%2F@5d27f099dbb2db5c45938090bbc4e29959e4df5d