aftership
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's purpose and capabilities are mostly coherent, and the CLI comes from the official npm package, so this is not confirmed malware. However, it routes AfterShip authentication and API traffic through Membrane rather than directly to AfterShip, creating a notable third-party trust and credential-forwarding boundary, plus an unpinned @latest install path.
Confidence: 88%Severity: 52%
Audit Metadata