salesforce-dmp

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's stated Salesforce purpose is plausible, and its install path is mostly legitimate, but the actual data flow is centered on Membrane as a third-party intermediary for authentication, request proxying, and credential refresh. That proxy architecture is a meaningful trust expansion beyond a direct Salesforce integration, so the skill is not malicious on its face but carries medium security risk from credential mediation and routed data flows.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 3, 2026, 12:55 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsalesforce-dmp%2F@5d365fd2c513d1973bce3732fb63c7da21ac966e