shipstation

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities mostly match its ShipStation integration purpose, and the Membrane CLI appears to be an official same-vendor npm package rather than an unverifiable payload. The main concern is data-flow integrity: ShipStation access and credential handling are mediated through Membrane’s proxy/service instead of direct calls to ShipStation, which adds a third-party trust boundary and moderate operational risk.

Confidence: 87%Severity: 54%
Audit Metadata
Analyzed At
Apr 2, 2026, 04:13 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fshipstation%2F@14ec8f640cd9cc121f953ba504857fcb7ea68a6e