alexishr

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly coherent as a Membrane-hosted AlexisHR integration and uses a legitimate npm-distributed CLI, but it routes credentials and HR data through Membrane instead of the official AlexisHR API. The main concerns are third-party credential/data custody and the unpinned global CLI install, not confirmed malware.

Confidence: 83%Severity: 52%
Audit Metadata
Analyzed At
May 2, 2026, 01:42 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Falexishr%2F@2eaaf46bd31eb6b19d52adb1456d6284331c6aa7
Security Audit — socket — alexishr