jobscore

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's core behavior is mostly coherent for a Membrane connector, and the CLI install path is legitimate, but all JobScore traffic and credentials are mediated by Membrane rather than direct official API use, and the JobScore/iCIMS documentation mismatch undermines trust. This looks more like a high-trust third-party integration wrapper than malware, with medium security risk driven by intermediary data flow and documentation inconsistency.

Confidence: 86%Severity: 57%
Audit Metadata
Analyzed At
Apr 3, 2026, 12:52 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fjobscore%2F@092bfd7586303f049afeaaa4c351ef97144a3d06