sendpulse

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose matches its capabilities, and the CLI install source appears legitimate, but it routes SendPulse authentication and API traffic through Membrane rather than directly to official SendPulse endpoints. That intermediary credential/data flow is a meaningful trust expansion, so this is not malicious but carries medium security risk.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 3, 2026, 09:51 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsendpulse%2F@65d01ec81a2ad675ad43d44361698b81215c824f