moosend

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly coherent with its stated Moosend integration purpose and uses an official npm-distributed Membrane CLI, so there is no strong evidence of malware or deceptive installation. However, all authenticated access is mediated through Membrane rather than direct Moosend APIs, meaning credentials and data flow through a third-party service, and the skill can trigger real-world actions like sending campaigns. This is better characterized as a legitimate but moderately risky proxy-based integration, not malicious content.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 21, 2026, 04:39 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmoosend%2F@319ee4463dea292331d807f101ac0484d1a1e216