uservoice

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is coherent for a Membrane-based UserVoice integration and uses an official npm package, so it is not outright malicious. However, all UserVoice access and auth are funneled through Membrane rather than official UserVoice endpoints, making the third-party data flow and credential mediation a meaningful medium risk.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 3, 2026, 04:22 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fuservoice%2F@907d668b7b42ecc378ec9e4df44bcef45cb0beac