ramp
Warn
Audited by Socket on Apr 22, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is mostly coherent for Ramp integration and uses an official npm-distributed CLI, but it routes authentication and Ramp operations through Membrane as an intermediary rather than directly to Ramp. That third-party credential/data brokering and unpinned `@latest` CLI usage create moderate security risk, though there is not enough evidence to call it malicious.
Confidence: 84%Severity: 58%
Audit Metadata