freshdesk

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities match its Freshdesk-management purpose, and the CLI comes from an official registry, so this is not outright malicious. However, authentication and API calls are routed through Membrane rather than directly to Freshdesk, creating a meaningful third-party credential and data-flow dependency; combined with unpinned CLI installation and write/delete actions, this makes the skill medium risk rather than benign.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
Apr 28, 2026, 08:15 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ffreshdesk%2F@59b8e71d2479d56703c81bfff0f3f709e020f01b