postman

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is coherent as a Postman integration, and its CLI install path appears to be official npm distribution, so it is not confirmed malware. However, it materially expands trust by routing authentication and Postman operations through Membrane’s third-party CLI/service, including server-side action discovery/building, which makes the data flow and credential handling broader than a direct Postman skill.

Confidence: 83%Severity: 62%
Audit Metadata
Analyzed At
Apr 22, 2026, 12:53 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpostman%2F@532210b9a760189610afc604e7382e27cdad1a6e