sumup

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities mostly align, and the install path is from official npm, not an opaque binary. However, it routes SumUp authentication and API traffic through Membrane rather than directly to SumUp, creating a third-party credential/data intermediary that is broader than a native integration. This is not confirmed malware, but the mediated data flow and mutable `@latest` usage make it medium risk.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 08:20 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsumup%2F@8422498ee1b6bec786fa79a8dd153591f71c5258