10to8
Warn
Audited by Socket on May 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s core behavior is mostly aligned with a 10to8 integration, and the CLI comes from an official npm package rather than an obviously malicious source. The main risk is architectural: all auth and data access are routed through Membrane as an intermediary, with unpinned CLI installation and server-side credential handling. This is not clearly malicious, but it increases trust and data-flow risk beyond a direct 10to8 API integration.
Confidence: 84%Severity: 58%
Audit Metadata