memberstack

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is purpose-aligned and uses an official npm-distributed CLI, so it does not look overtly malicious. However, it centralizes Memberstack access, authentication, and API traffic through Membrane's third-party CLI/proxy rather than using Memberstack's official API directly, which creates medium risk around credential forwarding, data flow expansion, and autonomous account changes.

Confidence: 85%Severity: 57%
Audit Metadata
Analyzed At
Mar 15, 2026, 07:42 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmemberstack%2F@079c380b2a7ce582428747053d7a8a1882ae485d