helpninja

Warn

Audited by Socket on Apr 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is largely coherent for a Membrane-based HelpNinja integration, and the CLI comes from an official npm package rather than a raw downloader. The main concern is data-flow integrity: instead of talking directly to HelpNinja's official API, all requests and delegated auth pass through Membrane's proxy, which expands trust and exposes HelpNinja data to a third-party intermediary. Overall this looks more like a legitimate integration wrapper than malware, but it carries moderate supply-chain and proxy-trust risk.

Confidence: 87%Severity: 52%
Audit Metadata
Analyzed At
Apr 25, 2026, 10:48 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fhelpninja%2F@96dd3ebd550368babd140f9a10847d70efa9003f