greythr

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly coherent with its stated GreytHR integration purpose and uses an official npm-distributed CLI, not a raw payload. However, it routes credentials and sensitive HR/payroll data through Membrane as a third-party intermediary rather than directly to official GreytHR endpoints, which creates a meaningful data-flow and trust-boundary risk. This looks like a legitimate integration pattern with elevated privacy/security exposure, not confirmed malware.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 21, 2026, 05:38 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgreythr%2F@1da95cc86f21d8611df1a13d9cafd07f462fea3e