formance

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose is coherent, and the CLI install path is plausibly official, but the actual integration routes authentication and Formance API traffic through Membrane as a third-party intermediary rather than direct Formance endpoints. That makes the skill higher-risk than a standard direct API integration, primarily due to credential/data handling and proxy-based data flow rather than clear malware behavior.

Confidence: 84%Severity: 66%
Audit Metadata
Analyzed At
Apr 2, 2026, 07:37 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fformance%2F@9b9e42810cb0d411825c62b572e4af26e2250025