peopleforce

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is largely coherent for a Membrane-based Peopleforce integration, and the install path uses a legitimate npm package rather than an opaque binary. The main risk is architectural: HRIS credentials and data are routed through Membrane's third-party platform and proxy instead of directly to Peopleforce, plus the docs encourage unpinned `@latest` CLI execution. This is not clearly malicious, but it carries meaningful trust and data-handling risk for sensitive employee records.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Apr 23, 2026, 02:43 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpeopleforce%2F@68768e930e5bed6c10c7e581beaeedd1ffbbdc3f