financialforce

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities broadly match its stated FinancialForce integration purpose, and the npm-hosted CLI appears to be the vendor's documented distribution path. However, the core design routes authentication and API traffic through Membrane's intermediary proxy instead of directly to official FinancialForce/Certinia endpoints, and it relies on an external CLI with unpinned execution examples. This is not strong evidence of malware, but it is a medium-risk third-party trust and data-routing pattern that warrants caution.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 12:41 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ffinancialforce%2F@4061efbbc72290b9da844f29e5a5c7f92577ea93