saleslens

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's core purpose is coherent, and the CLI comes from an official npm package rather than an obviously untrusted installer. However, all SalesLens access is mediated through Membrane's proxy/service instead of direct official SalesLens APIs, creating a third-party credential and data path that is broader than a simple integration guide. This looks more like a legitimate but trust-heavy managed gateway than malware.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 21, 2026, 04:41 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsaleslens%2F@e869ad1769f2001427132ac166bf7ba816334c59