recruiterflow
Warn
Audited by Socket on Apr 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's stated purpose is coherent, and the Membrane CLI appears to be an official same-vendor tool from npm rather than a stealth payload. However, the integration routes Recruiterflow authentication and data through Membrane as a third-party intermediary, which is broader than a direct Recruiterflow API integration and creates moderate credential/data-flow risk. No clear malware or deception is present, but the trust model should be explicit.
Confidence: 87%Severity: 62%
Audit Metadata