peoplehr

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly coherent with its stated PeopleHR integration purpose and uses a verifiable same-org npm CLI, but it introduces a third-party Membrane trust boundary for authentication and all API traffic, plus unpinned CLI execution and a broad proxy feature. This is not clearly malicious, but the indirect data flow and credential delegation make it higher risk than a direct official API integration.

Confidence: 87%Severity: 54%
Audit Metadata
Analyzed At
Apr 21, 2026, 09:06 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpeoplehr%2F@b5f9edf59631898f307cb92cd2963949ce9dedda