onespan

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's capabilities broadly match its purpose, and installation uses an official npm package rather than an unverifiable binary. However, the integration is not a direct OneSpan client: authentication, credential storage, and API requests are mediated by Membrane infrastructure, which creates a nontrivial third-party data flow that users may not expect from a vendor-specific skill.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 2, 2026, 04:40 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fonespan%2F@6edc7877f2e5f652cdc2d37a07f0d6359576f5a4