shippo

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's core purpose is coherent, and the install path uses an official npm package rather than an opaque binary. However, Shippo access is routed through Membrane's CLI and proxy instead of directly to Shippo official endpoints, creating intermediary credential and data-flow risk that is broader than a direct API integration. This looks more like a legitimate managed integration than malware, but the third-party proxy model raises medium security concerns.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Mar 23, 2026, 05:58 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fshippo%2F@7c8f32f26603122220c217cc1f4c877704f34cb4