square

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's general purpose matches Square operations, and the CLI install path is reasonably legitimate, but the core integration is mediated by Membrane rather than direct Square APIs. That intermediary design makes credentials and Square data flow through a third-party platform, which is disproportionate if the user expects a direct Square integration. No confirmed malware or overt credential theft is present, but the proxy/auth model creates medium security risk and trust concerns.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
Mar 13, 2026, 11:54 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsquare%2F@d375e070b230c3f73c9404584a180d962a069dc2