progress-sitefinity

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities broadly match its stated Sitefinity integration purpose, and the install path uses an official npm package rather than an unverified binary. The main concern is data-flow integrity: Sitefinity credentials and API traffic are routed through Membrane's intermediary platform and proxy, which expands trust beyond the official Progress service. This is disclosed and coherent, so it is not malicious, but it is medium risk due to credential mediation and third-party request proxying.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 05:39 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fprogress-sitefinity%2F@ca5304dd01bbe2a7e58b663fb0822467e6f93172