mercury

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core capability mostly matches a Mercury integration, and the CLI install path is legitimate, but the skill routes all Mercury access through Membrane as an intermediary, enabling broad credential/data handling outside Mercury’s official direct API flow. The incorrect Mercury docs link and vague description further weaken trust. Medium risk, not confirmed malware.

Confidence: 86%Severity: 62%
Audit Metadata
Analyzed At
Mar 15, 2026, 01:47 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmercury%2F@863c9f0ea256e2c5ca7c467b8f37179b726e2ff1