oracle-fusion-recruiting-cloud

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities fit its stated Oracle Recruiting integration purpose, and the CLI install path is consistent with Membrane's official distribution. The main risk is data-flow integrity: Oracle credentials and API traffic are mediated by Membrane's third-party connection/proxy layer rather than going directly to Oracle, plus the docs include unpinned `npx @latest` execution. This is not clearly malicious, but it meaningfully expands trust and data exposure beyond what the title alone suggests.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Apr 2, 2026, 04:11 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Foracle-fusion-recruiting-cloud%2F@145d6ecb2a02144a6bf5facef5fc6a24f3a03db4