sendblue

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly coherent and uses an official Membrane CLI install path, but it introduces a third-party intermediary for all Sendblue authentication and API traffic. The main risk is data-flow integrity and trust in Membrane as a proxy, plus unpinned CLI execution; this is not confirmed malware.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 21, 2026, 10:53 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsendblue%2F@43cc67356fc4580d4bf061480c2e4acbc89589a2