paystand

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is internally coherent for a Membrane-based Paystand integration and uses an official npm package, so it is not overtly malicious. However, it routes authentication and Paystand operations through Membrane rather than direct Paystand APIs, creating meaningful third-party credential/data exposure and moderate operational risk for finance-related actions.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 11:50 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpaystand%2F@2458a24e0650d43bb421021f219a6d27c0483ba9