ukg-pro

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's stated purpose matches its capabilities, and the CLI comes from an official npm package, so this is not obviously malicious. However, UKG Pro authentication and HR data are funneled through Membrane-managed connections and proxy endpoints rather than direct UKG APIs, creating a notable third-party trust and data-flow risk that is broader than a plain UKG integration.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
Apr 3, 2026, 03:32 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fukg-pro%2F@872e56d3bb1d2521b504f8269e8299a95b0a9660