incorta

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's stated purpose broadly matches Incorta integration, and the Membrane CLI/install path appears to be official. However, all Incorta access and credential handling are funneled through Membrane's intermediary platform, which stores credentials server-side and broadens the data trust boundary beyond Incorta. This is not clearly malicious, but the third-party proxy model, mutable CLI install, and ability to create/run potentially state-changing actions make the overall risk medium.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 22, 2026, 12:52 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fincorta%2F@fc56ff582668ff40edf7b4d3bf735358cdf3309f