fivetran

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly coherent with its stated Fivetran-management purpose, and the Membrane CLI install path appears official and proportionate. The main concern is data-flow integrity: Fivetran access is mediated through Membrane’s proxy/auth layer rather than directly to Fivetran, so a third party can observe and control API traffic. This is documented and not overtly deceptive, so it does not look malicious, but it carries medium risk due to intermediary credential/data handling and the ability to perform destructive account actions.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 24, 2026, 12:05 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ffivetran%2F@988e788174806fd0aa9a5973393450a7ed905c2e