shipcloud
Warn
Audited by Socket on Apr 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's purpose matches shipping operations, and the CLI install source appears legitimate, but the integration is not direct Shipcloud access. It routes authentication and operational data through Membrane, a third-party intermediary that stores connections and executes actions, which is a meaningful trust and data-flow expansion beyond a normal direct API skill.
Confidence: 87%Severity: 57%
Audit Metadata