showpad

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose is Showpad integration, but all authentication and API operations are brokered through Membrane instead of Showpad's official endpoints. The install path is relatively normal via npm, and scope is not obviously excessive, but the intermediary data flow and delegated credential handling make this a medium-risk third-party access pattern rather than a clean direct integration.

Confidence: 87%Severity: 66%
Audit Metadata
Analyzed At
Apr 21, 2026, 10:04 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fshowpad%2F@40fbf5fa7ecb5afb3cb341aecf5ebb47ca4918e9