razorpay

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and core capabilities are internally consistent, and the CLI install source is an official npm package from the same publisher, so this is not overt malware. However, all Razorpay operations and authentication are mediated by Membrane rather than going directly to Razorpay, creating a third-party credential/data gateway pattern and moderate trust expansion beyond a simple first-party integration.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Mar 17, 2026, 07:37 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Frazorpay%2F@1314272643c88f3aab5b0219b41b8112a4e95ef7