eversign

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core purpose is coherent for an Eversign admin skill, and the CLI install path is reasonably legitimate via npm. The main concern is that all authentication and API traffic are mediated by Membrane rather than going directly to Eversign, which introduces third-party credential/data handling and broad action capability, including destructive and email-sending operations.

Confidence: 82%Severity: 57%
Audit Metadata
Analyzed At
Apr 24, 2026, 10:05 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Feversign%2F@e69d0a9cdd159c7b42f8d5dfaa4216bfc4b593f9