workfront

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities largely match its stated Workfront integration purpose, and the CLI install path is from the official npm registry. However, all Workfront access is funneled through Membrane's third-party proxy/service instead of Adobe's native API path, so credentials and data are mediated by an additional vendor; this is documented and plausible, but it raises medium trust and data-flow risk rather than looking overtly malicious.

Confidence: 89%Severity: 56%
Audit Metadata
Analyzed At
Apr 2, 2026, 02:24 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fworkfront%2F@2389a98a59a007f56fb68d0fafcff5daba417e71