phonecom

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is coherent for Phone.com management, and the CLI install source appears same-vendor and official via npm, so this is not overtly malicious. However, the actual data flow routes Phone.com access through Membrane's proxy and CLI rather than direct official Phone.com API calls, creating third-party credential/data mediation risk; combined with unpinned npm and `npx @latest`, this makes the skill medium risk.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Apr 21, 2026, 11:48 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fphonecom%2F@3c7e68845ca9ae0b5adf956068b55c35d1c7a7b8