mendix

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is purpose-aligned and uses an official npm-distributed CLI, so it does not look overtly malicious. However, it requires a separate Membrane account and routes Mendix authentication and API traffic through Membrane’s proxy/service rather than directly to official Mendix endpoints, creating meaningful third-party credential and data-flow risk.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 3, 2026, 10:15 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmendix%2F@faaf2b266ff4c74bc80754db5453f94ff23a679a