snipcart

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

This skill is coherent with its stated purpose, but it is not a direct Snipcart integration: it depends on Membrane as a credential broker and API proxy. That makes it higher risk than a direct official API client, mainly due to third-party credential and data mediation, but there is no strong evidence of malware or deceptive install behavior.

Confidence: 89%Severity: 56%
Audit Metadata
Analyzed At
Apr 2, 2026, 01:43 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsnipcart%2F@6f03bc3b3a38f874387565e30ffc0475280e2bb4