rippling-hr

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Rippling HR skill appears coherent with its described purpose: it provides a Membrane-driven integration to Rippling HR via a trusted CLI, with authentication managed server-side and actions that map to Rippling endpoints. The install path and data flows are proportionate to the task, and there are no obvious credential leakage paths or supply-chain concerns in the provided manifest. Security posture is cautious ( Membrane-managed credentials, proxy usage ) but relies on Membrane’s security guarantees and network connectivity. Overall, the skill is BENIGN with MEDIUM-low risk; no exploit vectors or credential exposure patterns are evident from the description.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 07:06 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Frippling-hr%2F@553338165cddc6c57449af5bcc0d2098db43b013