alexishr
Warn
Audited by Socket on May 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is mostly coherent as a Membrane-hosted AlexisHR integration and uses a legitimate npm-distributed CLI, but it routes credentials and HR data through Membrane instead of the official AlexisHR API. The main concerns are third-party credential/data custody and the unpinned global CLI install, not confirmed malware.
Confidence: 83%Severity: 52%
Audit Metadata