jenkins-x

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is internally coherent as a Membrane-powered Jenkins X integration, and its install path uses an official npm package rather than an unverifiable binary. However, it routes Jenkins X access, auth, and action execution through Membrane instead of official Jenkins X APIs, creating a third-party credential/data mediation layer that is broader than the stated app-specific purpose.

Confidence: 87%Severity: 52%
Audit Metadata
Analyzed At
Apr 22, 2026, 02:45 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fjenkins-x%2F@aa083631aac56ee5287f74c9026bf88f7a6f1986