uipath

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s capabilities mostly match its UiPath integration purpose, and the Membrane CLI comes from a normal npm distribution path. The main concern is data-flow integrity: UiPath access and authentication are mediated by Membrane rather than going directly to UiPath APIs, so users must trust a third-party gateway with enterprise automation data and tokens. This is disclosed and plausibly intended, so it is not malicious, but it is a medium-risk integration pattern rather than a low-risk direct API skill.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Apr 2, 2026, 03:36 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fuipath%2F@2aa806b86ec578f8cb362eb0fc7777be9cbc29f0