marketing-miner

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent as a Membrane-based wrapper, and the CLI install path is from an official npm package, but the actual integration routes authentication and Marketing Miner data through Membrane rather than directly to official Marketing Miner APIs. This is not confirmed malware, yet it creates a notable third-party credential and data-flow trust boundary that is larger than the stated product integration alone suggests.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 21, 2026, 09:35 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmarketing-miner%2F@8d4e2a9581ff46517f286ad04cd6d28448a22f8b