sugarcrm

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill presents a coherent SugarCRM integration workflow using the Membrane CLI with built-in authentication management and proxy-based API access. Data flows are consistent with the stated purpose, and there is no evident use of unverifiable binaries or external exfiltration to unknown endpoints. Credential handling is centralized via Membrane, which is appropriate for this context, though explicit user-facing details about credential visibility and auditability would strengthen security assurances. Overall, the footprint is Benign with MEDIUM securityRisk due to proxy exposure considerations and centralized credential handling.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 09:00 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsugarcrm%2F@97523e0178998b940ee7bc8b399dfb8d4a731ff6