activeprospect

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is internally coherent for a Membrane-managed ActiveProspect integration and uses an official npm-distributed CLI, so this is not strong evidence of malware. However, it routes authentication, API calls, and returned data through Membrane as an intermediary rather than directly to ActiveProspect, and it relies on unpinned `@latest` CLI execution; this makes the skill medium risk despite appearing legitimate.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 02:49 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Factiveprospect%2F@1f18e06414de3efdff8464e0a4d06abd82c0a129
Security Audit — socket — activeprospect