moonclerk

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The MoonClerk skill is coherent with its stated purpose: it leverages Membrane as a controlled intermediary to authenticate, connect, query, and proxy MoonClerk API interactions. The reliance on Membrane for credential management and proxying is consistent with a developer-facing integration pattern. No direct local credential exposure is evident, and installs come from official registries (npm). Overall risk is moderate (securityRisk around 0.55) due to external proxying and token-based flows, but the architecture aligns with the described functionality.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 09:25 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmoonclerk%2F@ac7e45b16ff105dc7cafb23c34bb237c141dd73e