serply

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The main functionality is plausible and the CLI install path appears same-vendor and official, but the skill has notable inconsistencies: mismatched CRM-style description text, unpinned CLI execution, and all Serply access is brokered through Membrane rather than direct official API calls. This is not confirmed malware, but it expands trust and data flow to a third-party intermediary and deserves medium risk treatment.

Confidence: 87%Severity: 66%
Audit Metadata
Analyzed At
Mar 14, 2026, 08:25 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fserply%2F@57c58d35b55417c80165f7a1f0345662524d5df8