hellosign

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose matches HelloSign management, and its CLI install path is consistent with the Membrane publisher, so this is not clearly malicious. However, the integration is materially mediated by Membrane rather than direct HelloSign APIs, expanding third-party data access and enabling externally consequential actions like sending or canceling signature requests. Overall this is a coherent but medium-risk proxy-style integration skill.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 12:53 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fhellosign%2F@ac389004de3cc2cc61cf9b41aa99036c72677cca