fintechos

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly coherent with its stated FintechOS integration purpose and uses an official npm-distributed Membrane CLI, so this is not outright malicious. However, it routes authentication and API access through Membrane as an intermediary rather than direct FintechOS APIs, creating moderate third-party trust and data-flow risk; the unpinned `npx @latest` example adds minor supply-chain risk.

Confidence: 86%Severity: 53%
Audit Metadata
Analyzed At
Apr 23, 2026, 10:21 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ffintechos%2F@e7a790fb1b7cddcfab3c0d99c88a651b74558f5e