veriphone

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's functionality broadly matches its stated Veriphone purpose, and its CLI comes from an official npm package. However, all authentication and API traffic are routed through Membrane as an intermediary rather than directly to Veriphone, and the skill uses unpinned `@latest` CLI execution. This is not clearly malicious, but the third-party credential/data routing and mutable install path create medium security risk.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 05:11 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fveriphone%2F@62bd46c8050c08df14d30a3dcd3a9cff4737cfcc