payload-cms

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities broadly match its stated purpose, and the install path uses an official npm package rather than an unknown downloader. However, the core integration depends on routing authentication and API traffic through Membrane instead of talking directly to Payload CMS, creating a third-party credential and data handling trust boundary. Risk is medium due to intermediary data flow and mutable CLI installs, not clear malware.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 21, 2026, 07:44 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpayload-cms%2F@e3ab69442fc17f7e04de2a5df307c71ca271ee85