aftership

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities are mostly coherent, and the CLI comes from the official npm package, so this is not confirmed malware. However, it routes AfterShip authentication and API traffic through Membrane rather than directly to AfterShip, creating a notable third-party trust and credential-forwarding boundary, plus an unpinned @latest install path.

Confidence: 88%Severity: 52%
Audit Metadata
Analyzed At
Sep 16, 2026, 08:37 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Faftership%2F@459ab4eb37465d9f442d3b43c082abcface66b32deb8a845beef0f615f2f85e7
Security Audit — socket — aftership