tealium

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's Tealium purpose is plausible, and the Membrane CLI install path appears consistent with the publisher, so this is not confirmed malware. However, the integration is mediated through Membrane rather than direct Tealium APIs, requiring a separate third-party account and routing Tealium requests through a proxy, which creates meaningful data-flow and trust-boundary concerns disproportionate to a simple Tealium API skill.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 22, 2026, 10:49 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftealium%2F@d1b6d7526a2d73bb1c9254cb6969567ef201ba8a