sap-concur

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and capabilities mostly align, and the CLI comes from an official npm package rather than an unknown binary. However, the integration routes SAP Concur authentication and API access through Membrane as an intermediary service, and the proxy/request pattern broadens data exposure beyond a direct official API path. This is not confirmed malware, but it carries medium risk due to third-party credential/data handling and unpinned latest-version execution examples.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 22, 2026, 11:48 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsap-concur%2F@589d5e7321613981440c166df94d0b2193d3b90d