jupiterone

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly coherent with its stated JupiterOne integration purpose and uses a normal npm-installed CLI, so it is not strongly malicious. However, the actual data flow is through Membrane as an intermediary for auth, action execution, and proxy requests rather than directly to JupiterOne, which increases trust and exposure beyond a straightforward first-party integration.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 07:14 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fjupiterone%2F@09bc6410b921e8851a2505beadd899ee69c8948e