marketo

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's basic purpose is coherent, and the CLI install source appears legitimate, but the integration is architected to proxy all Marketo authentication and data access through Membrane rather than the official Marketo API. That third-party mediation, combined with remote action generation and impactful account actions, makes the data flow broader than expected for a Marketo skill.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Apr 30, 2026, 05:39 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmarketo%2F@e41d146bdaa18f1f69fcbdff5c1b087c76102d72