teamwork
Audited by Socket on Mar 11, 2026
1 alert found:
Obfuscated FileThe Teamwork skill presents a coherent, purpose-aligned integration using the Membrane CLI and its server-side credential management. Install sources (npm registry) are legitimate, and credential handling is described as centralized, reducing local secret exposure. Data flows through Membrane to Teamwork API endpoints, which is consistent with the stated objective of managing Teamwork data. While there are normal security considerations around credential handling and proxy data flow, there is no evident malicious activity or capability misalignment. Overall, the footprint is Benign to Suspect (leaning Benign) with moderate security risk due to external API exposure and potential logging exposure; ensure proper scope, least-privilege, and audit logging are enforced.