onespan
Warn
Audited by Socket on Apr 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's capabilities broadly match its purpose, and installation uses an official npm package rather than an unverifiable binary. However, the integration is not a direct OneSpan client: authentication, credential storage, and API requests are mediated by Membrane infrastructure, which creates a nontrivial third-party data flow that users may not expect from a vendor-specific skill.
Confidence: 86%Severity: 56%
Audit Metadata