appcues

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core purpose and capabilities are broadly coherent for an Appcues integration, and the install path is an official npm package rather than an unverified binary. The main concern is data-flow integrity: Appcues authentication and API traffic are mediated through Membrane's service and proxy instead of going directly to Appcues, creating moderate third-party trust and privacy risk; combined with broad write/delete capabilities and an imprecise, bloated scope description, this merits caution rather than a benign classification.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Apr 28, 2026, 08:47 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fappcues%2F@8fc0079e6d278497de91d957ed99343cf3416848
Security Audit — socket — appcues