follow-up-boss
Warn
Audited by Socket on Apr 22, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is broadly coherent with its stated purpose and uses an official-looking npm-distributed CLI, so it does not look malicious. However, all authentication and CRM traffic are funneled through Membrane rather than direct Follow Up Boss APIs, and the globally installed unpinned CLI plus third-party credential/data handling create meaningful trust and security risk.
Confidence: 85%Severity: 56%
Audit Metadata