shipworks

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly coherent and uses an official same-brand npm CLI, so it is not overtly malicious. The main risk is architectural: ShipWorks access and credentials are mediated through Membrane’s proxy/service instead of directly to ShipWorks, creating a moderate third-party data-handling and credential-forwarding concern, plus minor supply-chain risk from unpinned `npx @latest` usage.

Confidence: 87%Severity: 52%
Audit Metadata
Analyzed At
Apr 21, 2026, 04:12 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fshipworks%2F@a3389d2b27a05ef58936efbb481797ef2954b355