recruiterflow

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's stated purpose is coherent, and the Membrane CLI appears to be an official same-vendor tool from npm rather than a stealth payload. However, the integration routes Recruiterflow authentication and data through Membrane as a third-party intermediary, which is broader than a direct Recruiterflow API integration and creates moderate credential/data-flow risk. No clear malware or deception is present, but the trust model should be explicit.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
Apr 23, 2026, 03:58 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Frecruiterflow%2F@c46f4e312b0eeb83faf0c427052b00612e3db1c8