recruitee

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Benign-to-moderate risk: The skill's footprint is coherent with its stated purpose of integrating Recruitee via Membrane. It uses official tooling (Membrane CLI) and established OAuth flows, with proxy-based API calls to Recruitee. However, there are moderate security considerations around token storage, proxy data exposure, and how inputs/outputs are logged. No unverifiable binaries or credential-forwarding to unknown third-party software are described. Overall, the risk is manageable if Membrane enforces strict token handling, minimal logging, and proper access scoping. SecurityRisk: 0.55; Malware: 0.05.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 11:27 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Frecruitee%2F@99812ec2e5f21c88dac22b1d7fdd15d9459e7ffe