memberstack
Warn
Audited by Socket on Mar 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is purpose-aligned and uses an official npm-distributed CLI, so it does not look overtly malicious. However, it centralizes Memberstack access, authentication, and API traffic through Membrane's third-party CLI/proxy rather than using Memberstack's official API directly, which creates medium risk around credential forwarding, data flow expansion, and autonomous account changes.
Confidence: 85%Severity: 57%
Audit Metadata