agendor

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly coherent with its CRM-integration purpose and uses an official npm-distributed Membrane CLI tied to the stated publisher, so this is not strong evidence of malware. However, it routes Agendor authentication and data through Membrane's hosted platform rather than directly to Agendor, requires trusting a third-party CLI/service, and uses mutable `@latest` installation. Overall this is a legitimate-looking but medium-risk delegated-integration skill, not confirmed malicious.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 1, 2026, 10:24 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fagendor%2F@aa007eb93f2668d6efbd3ca96996e20300feb954