sendoso

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is coherent as a Membrane-based Sendoso integration and uses an official npm-published CLI, so it is not overtly malicious. However, all authentication and API traffic are mediated by Membrane rather than going directly to Sendoso, which expands trust and data exposure to a third-party intermediary and raises medium security risk.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 01:14 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsendoso%2F@3368e820e04547fc10f027bb6c549b7027c496ee