yapily

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly coherent with its stated Yapily integration purpose and uses an official same-vendor npm CLI, so install trust looks acceptable. The main risk is architectural: Yapily access and credentials are mediated through Membrane’s backend/proxy, meaning sensitive financial data and potentially payment actions flow through a third-party platform rather than directly to Yapily. This is proportionate to the product design but still a medium security risk due to financial-data sensitivity and intermediary trust.

Confidence: 87%Severity: 52%
Audit Metadata
Analyzed At
Apr 2, 2026, 07:39 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fyapily%2F@a6c6c9c0ed73c32a308f78bf7fd21510d6b64e47