ukg-pro-workforce-management

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's core capability matches its stated UKG integration purpose, and the CLI install path appears vendor-consistent and registry-based rather than an obvious malware lure. However, the integration is materially mediated by Membrane: authentication, credential refresh, actions, and raw API proxying all flow through a third-party service instead of directly to official UKG endpoints, which increases trust and data-exposure risk beyond a normal direct connector.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 03:13 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fukg-pro-workforce-management%2F@a58f261bd46b32a7772280f4c183615faefd24e8