shopee

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's core behavior is coherent for a Membrane-hosted Shopee integration, and the CLI comes from an official npm package tied to the same publisher. However, all Shopee auth and data access are routed through Membrane rather than direct Shopee APIs, so the user must trust a third-party gateway with credentials, intents, and retrieved data; combined with a mutable `@latest` global install, this makes it medium risk rather than benign.

Confidence: 84%Severity: 53%
Audit Metadata
Analyzed At
Apr 21, 2026, 12:11 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fshopee%2F@b12294c268ed86c976e21b34dd553ca98796e40a