jenkins-x
Warn
Audited by Socket on Apr 22, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is internally coherent as a Membrane-powered Jenkins X integration, and its install path uses an official npm package rather than an unverifiable binary. However, it routes Jenkins X access, auth, and action execution through Membrane instead of official Jenkins X APIs, creating a third-party credential/data mediation layer that is broader than the stated app-specific purpose.
Confidence: 87%Severity: 52%
Audit Metadata