lever

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated ATS integration purpose fits the capabilities, and the CLI install path appears official, but the skill routes authentication and API traffic through Membrane rather than directly to Lever. That intermediary trust and credential forwarding are proportionately risky even though they are openly documented, so this is better classified as medium-risk suspicious rather than malicious.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
Mar 14, 2026, 08:43 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Flever%2F@5ecd08c9d56dcb64b440a74fc6e0672f28fc40d0