10to8

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s core behavior is mostly aligned with a 10to8 integration, and the CLI comes from an official npm package rather than an obviously malicious source. The main risk is architectural: all auth and data access are routed through Membrane as an intermediary, with unpinned CLI installation and server-side credential handling. This is not clearly malicious, but it increases trust and data-flow risk beyond a direct 10to8 API integration.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
May 1, 2026, 09:13 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2F10to8%2F@a2b3de7b95b1218fbcfc50cdfbdf2cef98193e79
Security Audit — socket — 10to8