plaid

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities are mostly coherent, and the CLI comes from a standard registry under branding consistent with the publisher. However, the skill is presented as a Plaid integration while all sensitive authentication and data access are mediated by third-party Membrane infrastructure, not Plaid's official tooling, and it uses mutable latest-tag installs. This is not confirmed malware, but it expands trust and data flow beyond what a direct Plaid integration would normally require.

Confidence: 82%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 11:50 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fplaid%2F@1628a34455e4913911c10122ebf017585a23ea20