lime-crm

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly aligned with CRM integration, but it routes authentication and all Lime CRM operations through Membrane rather than directly to official Lime endpoints. Because the installer is same-vendor and from npm, this is not malicious by itself; however, the third-party mediation layer, mutable CLI install, and ability to create/run generated actions make the trust footprint larger than the description suggests.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 21, 2026, 09:35 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Flime-crm%2F@6e804c6abb9dc6f92ec3be49fc32de91bb82d1c6